CGRC · Question #426
When an AO submits the security authorization decision, what responses should the ISO expect to receive? Response:
The correct answer is A. Authorized to operate (ATO) or denial authorization to operate (DATO), the conditions for the. The Authorizing Official's security authorization decision typically results in either an Authorization to Operate (ATO) or a Denial of Authorization to Operate (DATO), along with any specific conditions or limitations associated with that decision.
Question
When an AO submits the security authorization decision, what responses should the ISO expect to receive? Response:
Options
- AAuthorized to operate (ATO) or denial authorization to operate (DATO), the conditions for the
- BAuthorized to operate (ATO) or denial authorization to operate (DATO), the list of security controls
- CAuthorized to operate (ATO) or denial authorization to operate (DATO), and the conditions for the
- DA plan of action and milestones (POA&M), the conditions for the authorization placed on the
How the community answered
(52 responses)- A92% (48)
- B2% (1)
- C2% (1)
- D4% (2)
Why each option
The Authorizing Official's security authorization decision typically results in either an Authorization to Operate (ATO) or a Denial of Authorization to Operate (DATO), along with any specific conditions or limitations associated with that decision.
The primary outcomes of an AO's authorization decision are an Authorization to Operate (ATO) or a Denial of Authorization to Operate (DATO). An ATO is often accompanied by specific conditions, such as requirements for ongoing monitoring or mitigation of residual risks, which the ISO must be aware of and adhere to.
While security controls are assessed to reach the decision, the list of controls themselves is not the direct output of the AO's final decision; rather, the decision is based on the effectiveness of those controls and the associated risk.
This option is very similar to A but less complete in phrasing; option A explicitly mentions the 'conditions for the' authorization, clearly indicating accompanying terms.
A Plan of Action and Milestones (POA&M) is a document detailing remediation efforts for vulnerabilities, not the final authorization decision itself.
Concept tested: AO authorization decision outcomes
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.