CGRC · Question #489
Ongoing authorizations and reporting can be time- and event-driven. Which official has the primary responsibility for ongoing authorizations? Response:
The correct answer is C. Authorizing Official. The Authorizing Official (AO) maintains the ultimate authority and responsibility for granting and maintaining the Authorization to Operate (ATO) for an information system, which includes overseeing ongoing authorizations.
Question
Ongoing authorizations and reporting can be time- and event-driven. Which official has the primary responsibility for ongoing authorizations? Response:
Options
- ACommon Control Provider
- BInformation Owner
- CAuthorizing Official
- DInformation System Owner
How the community answered
(56 responses)- A7% (4)
- B4% (2)
- C88% (49)
- D2% (1)
Why each option
The Authorizing Official (AO) maintains the ultimate authority and responsibility for granting and maintaining the Authorization to Operate (ATO) for an information system, which includes overseeing ongoing authorizations.
A Common Control Provider is responsible for developing, implementing, assessing, and monitoring common controls that other systems inherit, not for the authorization decision itself.
An Information Owner is responsible for the data or information within a system, not the overall system authorization.
The Authorizing Official (AO) is the senior federal official or executive responsible for making an organizational risk determination and for issuing an authorization for an information system to operate. This responsibility extends to ongoing authorizations, ensuring that the system continues to meet security requirements and operate within an acceptable risk posture throughout its lifecycle.
An Information System Owner is responsible for the system's operations and security throughout its lifecycle, supporting the AO's decision but not having the authority to authorize operation.
Concept tested: Authorizing Official responsibilities - RMF
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.