nerdexam
(ISC)2

CGRC · Question #539

System authorization is now used to refer to which of the following terms? Response:

The correct answer is B. Certification and accreditation. The term "system authorization" is now used by NIST, particularly within the Risk Management Framework (RMF), to refer to the comprehensive process that succeeded the older "Certification and Accreditation" (C&A). It encompasses both the technical assessment (certification) and…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

System authorization is now used to refer to which of the following terms? Response:

Options

  • ASystem security declaration
  • BCertification and accreditation
  • CSecurity test and evaluation
  • DContinuous monitoring

How the community answered

(20 responses)
  • B
    90% (18)
  • C
    5% (1)
  • D
    5% (1)

Why each option

The term "system authorization" is now used by NIST, particularly within the Risk Management Framework (RMF), to refer to the comprehensive process that succeeded the older "Certification and Accreditation" (C&A). It encompasses both the technical assessment (certification) and the formal management decision (accreditation) to operate a system.

ASystem security declaration

System security declaration is not a standard term used to replace C&A; while a declaration might be part of the authorization, it's not the equivalent overall process.

BCertification and accreditationCorrect

System authorization is the modernized term used in the Risk Management Framework (RMF) that replaces the legacy "Certification and Accreditation (C&A)" process, encompassing both the technical security review and the formal decision to operate an information system.

CSecurity test and evaluation

Security test and evaluation (ST&E) is an activity conducted within the authorization process (specifically during the assessment phase), but it is not the overarching term for authorization itself.

DContinuous monitoring

Continuous monitoring is RMF Step 7, an ongoing activity after authorization, not the term for the entire authorization process.

Concept tested: RMF terminology - Authorization replacing C&A

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#System Authorization#Certification and Accreditation (C&A)#NIST RMF#Authorization to Operate (ATO)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice