nerdexam
(ISC)2

CGRC · Question #507

Which authorization approach considers time elapsed since the authorization results were produced, the environment of operation, the criticality/sensitivity of the information, and the risk tolerance

The correct answer is A. Leveraged. The Leveraged authorization approach involves an organization accepting existing authorization results from another entity after considering factors like the time elapsed, operating environment, information criticality, and risk tolerance.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which authorization approach considers time elapsed since the authorization results were produced, the environment of operation, the criticality/sensitivity of the information, and the risk tolerance of the other organization? Response:

Options

  • ALeveraged
  • BSingle
  • CJoint
  • DSite specific

How the community answered

(60 responses)
  • A
    90% (54)
  • B
    2% (1)
  • C
    2% (1)
  • D
    7% (4)

Why each option

The Leveraged authorization approach involves an organization accepting existing authorization results from another entity after considering factors like the time elapsed, operating environment, information criticality, and risk tolerance.

ALeveragedCorrect

A Leveraged authorization is where an organization utilizes a security authorization package produced by another entity for its own systems. To do so, the organization must perform due diligence, evaluating specific criteria such as the age of the authorization, the alignment of the operating environments, the sensitivity of the information involved, and its own organizational risk tolerance to ensure the authorization remains valid and appropriate.

BSingle

A 'Single' authorization approach refers to an organization conducting its own authorization for its own system without relying on external packages.

CJoint

A 'Joint' authorization approach involves multiple organizations collaborating to produce a single authorization package for a system shared between them.

DSite specific

A 'Site specific' authorization refers to an authorization tailored to a particular physical location or facility, which is not the primary characteristic described.

Concept tested: RMF Authorization Approaches - Leveraged

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Leveraged Authorization#Risk Management#Authorization Decision#NIST RMF

Community Discussion

No community discussion yet for this question.

Full CGRC Practice