nerdexam
(ISC)2

CGRC · Question #451

The authorizing official may choose to authorize the system to operate only for a short period of time if it is necessary to test the system in the environment of operation before all controls are…

The correct answer is D. Interim authority to test. This question describes a temporary authorization to operate a system for testing purposes when not all security controls are fully implemented, asking for the formal term for this type of authorization.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The authorizing official may choose to authorize the system to operate only for a short period of time if it is necessary to test the system in the environment of operation before all controls are fully in place. This type of authorization was formally referred to as:

Response:

Options

  • AAuthorization to test
  • BAuthorization to use common controls
  • CAuthorization to operate
  • DInterim authority to test

How the community answered

(26 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    92% (24)

Why each option

This question describes a temporary authorization to operate a system for testing purposes when not all security controls are fully implemented, asking for the formal term for this type of authorization.

AAuthorization to test

“Authorization to test” is not a formally recognized authorization type in NIST RMF terminology for temporary system operation.

BAuthorization to use common controls

“Authorization to use common controls” relates to the approval for an organization to inherit common security controls from another system, not a temporary operating status.

CAuthorization to operate

“Authorization to operate” (ATO) is the formal decision to allow a system to operate, implying all controls are in place and effective, which contradicts the scenario of controls not being fully in place.

DInterim authority to testCorrect

Interim Authority to Test (IATT) refers to a temporary authorization granted by an authorizing official to permit the operation of an information system for a specified period, typically to test its functionality and security in an operational environment before granting full Authorization to Operate (ATO). This allows for critical testing and evaluation while acknowledging that some controls may still be undergoing implementation or validation.

Concept tested: NIST RMF Authorization Types

Source: https://csrc.nist.gov/glossary/term/interim-authorization-to-test

Topics

#Authorization Process#Interim Authority to Test (IATT)#Authorizing Official (AO)#Risk Management Framework (RMF)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice