CGRC · Question #539
System authorization is now used to refer to which of the following terms? Response:
The correct answer is B. Certification and accreditation. The term "system authorization" is now used by NIST, particularly within the Risk Management Framework (RMF), to refer to the comprehensive process that succeeded the older "Certification and Accreditation" (C&A). It encompasses both the technical assessment (certification) and…
Question
System authorization is now used to refer to which of the following terms? Response:
Options
- ASystem security declaration
- BCertification and accreditation
- CSecurity test and evaluation
- DContinuous monitoring
How the community answered
(20 responses)- B90% (18)
- C5% (1)
- D5% (1)
Why each option
The term "system authorization" is now used by NIST, particularly within the Risk Management Framework (RMF), to refer to the comprehensive process that succeeded the older "Certification and Accreditation" (C&A). It encompasses both the technical assessment (certification) and the formal management decision (accreditation) to operate a system.
System security declaration is not a standard term used to replace C&A; while a declaration might be part of the authorization, it's not the equivalent overall process.
System authorization is the modernized term used in the Risk Management Framework (RMF) that replaces the legacy "Certification and Accreditation (C&A)" process, encompassing both the technical security review and the formal decision to operate an information system.
Security test and evaluation (ST&E) is an activity conducted within the authorization process (specifically during the assessment phase), but it is not the overarching term for authorization itself.
Continuous monitoring is RMF Step 7, an ongoing activity after authorization, not the term for the entire authorization process.
Concept tested: RMF terminology - Authorization replacing C&A
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.