nerdexam
(ISC)2

CGRC · Question #424

An Authorizing Official plays the role of an approver. What are the responsibilities of an Authorizing Official? Each correct answer represents a complete solution. Choose all that apply. Response:

The correct answer is B. Determining the requirement of reauthorization and reauthorizing information systems when C. Reviewing security status reports and critical security documents D. Ascertaining the security posture of the organization's information system. An Authorizing Official (AO) is responsible for making risk-based decisions about system operation, which includes reviewing security documentation, determining system reauthorization needs, and understanding the overall security posture.

Compliance Maintenance

Question

An Authorizing Official plays the role of an approver. What are the responsibilities of an Authorizing Official? Each correct answer represents a complete solution. Choose all that apply. Response:

Options

  • AEstablishing and implementing the organization's continuous monitoring program
  • BDetermining the requirement of reauthorization and reauthorizing information systems when
  • CReviewing security status reports and critical security documents
  • DAscertaining the security posture of the organization's information system

How the community answered

(50 responses)
  • A
    12% (6)
  • B
    88% (44)

Why each option

An Authorizing Official (AO) is responsible for making risk-based decisions about system operation, which includes reviewing security documentation, determining system reauthorization needs, and understanding the overall security posture.

AEstablishing and implementing the organization's continuous monitoring program

Establishing and implementing the continuous monitoring program is typically a responsibility of the Chief Information Security Officer (CISO) or Information System Security Officer (ISSO), not the Authorizing Official directly.

BDetermining the requirement of reauthorization and reauthorizing information systems whenCorrect

The AO determines the need for reauthorization and issues reauthorization decisions for information systems, ensuring ongoing acceptable risk levels.

CReviewing security status reports and critical security documentsCorrect

The AO reviews security status reports, Plans of Action and Milestones (POA&Ms), and other critical security documents to inform their authorization decisions.

DAscertaining the security posture of the organization's information systemCorrect

The AO is ultimately responsible for understanding and accepting the security posture of an information system based on assessed risk, prior to granting an Authorization to Operate (ATO).

Concept tested: Authorizing Official (AO) responsibilities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Authorizing Official (AO)#Risk Management Framework (RMF) roles#Authorization to Operate (ATO)#System Reauthorization

Community Discussion

No community discussion yet for this question.

Full CGRC Practice