nerdexam
(ISC)2

CGRC · Question #396

Which RMF role can be appointed at the discretion of the Approving/Authorization Authority? Response:

The correct answer is A. Designated Representative (DR). The Approving/Authorization Authority can appoint a Designated Representative to act on their behalf within the Risk Management Framework.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which RMF role can be appointed at the discretion of the Approving/Authorization Authority? Response:

Options

  • ADesignated Representative (DR)
  • BSystem Development Life-Cycle (SDLC)
  • CRisk Management Framework (RMF)
  • DPlan of Action and Milestones (POAM)

How the community answered

(36 responses)
  • A
    92% (33)
  • B
    3% (1)
  • D
    6% (2)

Why each option

The Approving/Authorization Authority can appoint a Designated Representative to act on their behalf within the Risk Management Framework.

ADesignated Representative (DR)Correct

The Designated Representative (DR) is a role that can be appointed by the Authorizing Official (AO) or Approving Authority to perform specific RMF responsibilities on their behalf. This allows the AO to delegate certain tasks while retaining ultimate accountability for the authorization decision.

BSystem Development Life-Cycle (SDLC)

SDLC (System Development Life-Cycle) is a process, not a role.

CRisk Management Framework (RMF)

RMF (Risk Management Framework) is a process, not a role.

DPlan of Action and Milestones (POAM)

POAM (Plan of Action and Milestones) is a document or management tool, not a role.

Concept tested: NIST RMF roles (Designated Representative)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#RMF Roles#Authorization Authority#Designated Representative#NIST SP 800-37

Community Discussion

No community discussion yet for this question.

Full CGRC Practice