nerdexam
(ISC)2

CGRC · Question #472

Risk assessments at the organizational level leverages aggregated information from system-level risk assessment results, continuous monitoring and any startegic risk considerations relevant to the…

The correct answer is C. Authorization limit date. The results of organizational-level risk assessments are essential for determining the authorization limit date for systems, reflecting the acceptable duration of a system's operational authorization based on its risk posture.

System Compliance

Question

Risk assessments at the organizational level leverages aggregated information from system-level risk assessment results, continuous monitoring and any startegic risk considerations relevant to the organization. Which if the follwing reasons best explain why the results of risk assessments is essential to the organization? Response:

Options

  • AThe monitoring frequency for each security control is based on which of the following?
  • BResponse:
  • CAuthorization limit date
  • DDecisions of the SCA
  • EOrganizational continuous monitoring strategy
  • FNone of the above

How the community answered

(42 responses)
  • A
    5% (2)
  • C
    79% (33)
  • D
    12% (5)
  • E
    2% (1)
  • F
    2% (1)

Why each option

The results of organizational-level risk assessments are essential for determining the authorization limit date for systems, reflecting the acceptable duration of a system's operational authorization based on its risk posture.

AThe monitoring frequency for each security control is based on which of the following?

This choice is presented as a question, not an answer, and thus is technically incorrect.

BResponse:

This choice is a label ('Response:'), not an answer to the question.

CAuthorization limit dateCorrect

The results of organizational risk assessments are crucial for establishing an authorization limit date, as they provide insight into the aggregated risks that could impact an organization's systems and missions. This date signifies the validity period of a system's Authorization to Operate (ATO), ensuring that systems are regularly re-evaluated against current risks to maintain an acceptable security posture.

DDecisions of the SCA

While decisions of the Security Control Assessor (SCA) are informed by risk assessments, the 'authorization limit date' is a specific output related to the validity period of authorization.

EOrganizational continuous monitoring strategy

The organizational continuous monitoring strategy is a process for ongoing oversight, not the direct reason why risk assessment results determine an authorization limit date.

FNone of the above

Since C is a correct explanation based on the provided answer, this option is incorrect.

Concept tested: Risk assessment impact on authorization lifecycle

Source: docs.federalpay.org/agencies/nist-fips/nist-sp-800-37-rev-2-risk-management-framework-for-information-systems-and-organizations/

Topics

#Risk Assessment#Authorization to Operate (ATO)#Authorization Limit Date#System Compliance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice