CGRC · Question #507
Which authorization approach considers time elapsed since the authorization results were produced, the environment of operation, the criticality/sensitivity of the information, and the risk tolerance
The correct answer is A. Leveraged. The Leveraged authorization approach involves an organization accepting existing authorization results from another entity after considering factors like the time elapsed, operating environment, information criticality, and risk tolerance.
Question
Which authorization approach considers time elapsed since the authorization results were produced, the environment of operation, the criticality/sensitivity of the information, and the risk tolerance of the other organization? Response:
Options
- ALeveraged
- BSingle
- CJoint
- DSite specific
How the community answered
(60 responses)- A90% (54)
- B2% (1)
- C2% (1)
- D7% (4)
Why each option
The Leveraged authorization approach involves an organization accepting existing authorization results from another entity after considering factors like the time elapsed, operating environment, information criticality, and risk tolerance.
A Leveraged authorization is where an organization utilizes a security authorization package produced by another entity for its own systems. To do so, the organization must perform due diligence, evaluating specific criteria such as the age of the authorization, the alignment of the operating environments, the sensitivity of the information involved, and its own organizational risk tolerance to ensure the authorization remains valid and appropriate.
A 'Single' authorization approach refers to an organization conducting its own authorization for its own system without relying on external packages.
A 'Joint' authorization approach involves multiple organizations collaborating to produce a single authorization package for a system shared between them.
A 'Site specific' authorization refers to an authorization tailored to a particular physical location or facility, which is not the primary characteristic described.
Concept tested: RMF Authorization Approaches - Leveraged
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.