nerdexam
(ISC)2

CGRC · Question #426

When an AO submits the security authorization decision, what responses should the ISO expect to receive? Response:

The correct answer is A. Authorized to operate (ATO) or denial authorization to operate (DATO), the conditions for the. The Authorizing Official's security authorization decision typically results in either an Authorization to Operate (ATO) or a Denial of Authorization to Operate (DATO), along with any specific conditions or limitations associated with that decision.

System Compliance

Question

When an AO submits the security authorization decision, what responses should the ISO expect to receive? Response:

Options

  • AAuthorized to operate (ATO) or denial authorization to operate (DATO), the conditions for the
  • BAuthorized to operate (ATO) or denial authorization to operate (DATO), the list of security controls
  • CAuthorized to operate (ATO) or denial authorization to operate (DATO), and the conditions for the
  • DA plan of action and milestones (POA&M), the conditions for the authorization placed on the

How the community answered

(52 responses)
  • A
    92% (48)
  • B
    2% (1)
  • C
    2% (1)
  • D
    4% (2)

Why each option

The Authorizing Official's security authorization decision typically results in either an Authorization to Operate (ATO) or a Denial of Authorization to Operate (DATO), along with any specific conditions or limitations associated with that decision.

AAuthorized to operate (ATO) or denial authorization to operate (DATO), the conditions for theCorrect

The primary outcomes of an AO's authorization decision are an Authorization to Operate (ATO) or a Denial of Authorization to Operate (DATO). An ATO is often accompanied by specific conditions, such as requirements for ongoing monitoring or mitigation of residual risks, which the ISO must be aware of and adhere to.

BAuthorized to operate (ATO) or denial authorization to operate (DATO), the list of security controls

While security controls are assessed to reach the decision, the list of controls themselves is not the direct output of the AO's final decision; rather, the decision is based on the effectiveness of those controls and the associated risk.

CAuthorized to operate (ATO) or denial authorization to operate (DATO), and the conditions for the

This option is very similar to A but less complete in phrasing; option A explicitly mentions the 'conditions for the' authorization, clearly indicating accompanying terms.

DA plan of action and milestones (POA&M), the conditions for the authorization placed on the

A Plan of Action and Milestones (POA&M) is a document detailing remediation efforts for vulnerabilities, not the final authorization decision itself.

Concept tested: AO authorization decision outcomes

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#RMF Authorization Decision#ATO/DATO#Authorizing Official (AO)#Authorization Conditions

Community Discussion

No community discussion yet for this question.

Full CGRC Practice