CGRC · Question #396
Which RMF role can be appointed at the discretion of the Approving/Authorization Authority? Response:
The correct answer is A. Designated Representative (DR). The Approving/Authorization Authority can appoint a Designated Representative to act on their behalf within the Risk Management Framework.
Question
Which RMF role can be appointed at the discretion of the Approving/Authorization Authority? Response:
Options
- ADesignated Representative (DR)
- BSystem Development Life-Cycle (SDLC)
- CRisk Management Framework (RMF)
- DPlan of Action and Milestones (POAM)
How the community answered
(36 responses)- A92% (33)
- B3% (1)
- D6% (2)
Why each option
The Approving/Authorization Authority can appoint a Designated Representative to act on their behalf within the Risk Management Framework.
The Designated Representative (DR) is a role that can be appointed by the Authorizing Official (AO) or Approving Authority to perform specific RMF responsibilities on their behalf. This allows the AO to delegate certain tasks while retaining ultimate accountability for the authorization decision.
SDLC (System Development Life-Cycle) is a process, not a role.
RMF (Risk Management Framework) is a process, not a role.
POAM (Plan of Action and Milestones) is a document or management tool, not a role.
Concept tested: NIST RMF roles (Designated Representative)
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.