CGRC · Question #424
An Authorizing Official plays the role of an approver. What are the responsibilities of an Authorizing Official? Each correct answer represents a complete solution. Choose all that apply. Response:
The correct answer is B. Determining the requirement of reauthorization and reauthorizing information systems when C. Reviewing security status reports and critical security documents D. Ascertaining the security posture of the organization's information system. An Authorizing Official (AO) is responsible for making risk-based decisions about system operation, which includes reviewing security documentation, determining system reauthorization needs, and understanding the overall security posture.
Question
An Authorizing Official plays the role of an approver. What are the responsibilities of an Authorizing Official? Each correct answer represents a complete solution. Choose all that apply. Response:
Options
- AEstablishing and implementing the organization's continuous monitoring program
- BDetermining the requirement of reauthorization and reauthorizing information systems when
- CReviewing security status reports and critical security documents
- DAscertaining the security posture of the organization's information system
How the community answered
(50 responses)- A12% (6)
- B88% (44)
Why each option
An Authorizing Official (AO) is responsible for making risk-based decisions about system operation, which includes reviewing security documentation, determining system reauthorization needs, and understanding the overall security posture.
Establishing and implementing the continuous monitoring program is typically a responsibility of the Chief Information Security Officer (CISO) or Information System Security Officer (ISSO), not the Authorizing Official directly.
The AO determines the need for reauthorization and issues reauthorization decisions for information systems, ensuring ongoing acceptable risk levels.
The AO reviews security status reports, Plans of Action and Milestones (POA&Ms), and other critical security documents to inform their authorization decisions.
The AO is ultimately responsible for understanding and accepting the security posture of an information system based on assessed risk, prior to granting an Authorization to Operate (ATO).
Concept tested: Authorizing Official (AO) responsibilities
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.