nerdexam
(ISC)2

CGRC · Question #489

Ongoing authorizations and reporting can be time- and event-driven. Which official has the primary responsibility for ongoing authorizations? Response:

The correct answer is C. Authorizing Official. The Authorizing Official (AO) maintains the ultimate authority and responsibility for granting and maintaining the Authorization to Operate (ATO) for an information system, which includes overseeing ongoing authorizations.

Compliance Maintenance

Question

Ongoing authorizations and reporting can be time- and event-driven. Which official has the primary responsibility for ongoing authorizations? Response:

Options

  • ACommon Control Provider
  • BInformation Owner
  • CAuthorizing Official
  • DInformation System Owner

How the community answered

(56 responses)
  • A
    7% (4)
  • B
    4% (2)
  • C
    88% (49)
  • D
    2% (1)

Why each option

The Authorizing Official (AO) maintains the ultimate authority and responsibility for granting and maintaining the Authorization to Operate (ATO) for an information system, which includes overseeing ongoing authorizations.

ACommon Control Provider

A Common Control Provider is responsible for developing, implementing, assessing, and monitoring common controls that other systems inherit, not for the authorization decision itself.

BInformation Owner

An Information Owner is responsible for the data or information within a system, not the overall system authorization.

CAuthorizing OfficialCorrect

The Authorizing Official (AO) is the senior federal official or executive responsible for making an organizational risk determination and for issuing an authorization for an information system to operate. This responsibility extends to ongoing authorizations, ensuring that the system continues to meet security requirements and operate within an acceptable risk posture throughout its lifecycle.

DInformation System Owner

An Information System Owner is responsible for the system's operations and security throughout its lifecycle, supporting the AO's decision but not having the authority to authorize operation.

Concept tested: Authorizing Official responsibilities - RMF

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Authorizing Official#RMF Roles#Ongoing Authorization#Continuous Monitoring

Community Discussion

No community discussion yet for this question.

Full CGRC Practice