CGRC · Question #472
Risk assessments at the organizational level leverages aggregated information from system-level risk assessment results, continuous monitoring and any startegic risk considerations relevant to the…
The correct answer is C. Authorization limit date. The results of organizational-level risk assessments are essential for determining the authorization limit date for systems, reflecting the acceptable duration of a system's operational authorization based on its risk posture.
Question
Risk assessments at the organizational level leverages aggregated information from system-level risk assessment results, continuous monitoring and any startegic risk considerations relevant to the organization. Which if the follwing reasons best explain why the results of risk assessments is essential to the organization? Response:
Options
- AThe monitoring frequency for each security control is based on which of the following?
- BResponse:
- CAuthorization limit date
- DDecisions of the SCA
- EOrganizational continuous monitoring strategy
- FNone of the above
How the community answered
(42 responses)- A5% (2)
- C79% (33)
- D12% (5)
- E2% (1)
- F2% (1)
Why each option
The results of organizational-level risk assessments are essential for determining the authorization limit date for systems, reflecting the acceptable duration of a system's operational authorization based on its risk posture.
This choice is presented as a question, not an answer, and thus is technically incorrect.
This choice is a label ('Response:'), not an answer to the question.
The results of organizational risk assessments are crucial for establishing an authorization limit date, as they provide insight into the aggregated risks that could impact an organization's systems and missions. This date signifies the validity period of a system's Authorization to Operate (ATO), ensuring that systems are regularly re-evaluated against current risks to maintain an acceptable security posture.
While decisions of the Security Control Assessor (SCA) are informed by risk assessments, the 'authorization limit date' is a specific output related to the validity period of authorization.
The organizational continuous monitoring strategy is a process for ongoing oversight, not the direct reason why risk assessment results determine an authorization limit date.
Since C is a correct explanation based on the provided answer, this option is incorrect.
Concept tested: Risk assessment impact on authorization lifecycle
Source: docs.federalpay.org/agencies/nist-fips/nist-sp-800-37-rev-2-risk-management-framework-for-information-systems-and-organizations/
Topics
Community Discussion
No community discussion yet for this question.