nerdexam
(ISC)2

CGRC · Question #557

What key information is used by the authorizing official (AO) to assist with the risk determination of an information system (IS)? Response:

The correct answer is A. Security authorization package (SAP). The Authorizing Official (AO) relies on the comprehensive Security Authorization Package (SAP) as key information to assist in making an informed risk determination for an information system.

System Compliance

Question

What key information is used by the authorizing official (AO) to assist with the risk determination of an information system (IS)? Response:

Options

  • ASecurity authorization package (SAP)
  • BPlan of action and milestones (POA&M)
  • CSecurity plan (SP)
  • DInterconnection security agreement (ISA)

How the community answered

(34 responses)
  • A
    94% (32)
  • C
    3% (1)
  • D
    3% (1)

Why each option

The Authorizing Official (AO) relies on the comprehensive Security Authorization Package (SAP) as key information to assist in making an informed risk determination for an information system.

ASecurity authorization package (SAP)Correct

The Security Authorization Package (SAP) is a complete collection of documentation, including the security plan, security assessment report, and plan of action and milestones (POA&M), which provides the AO with all necessary evidence to evaluate the system's security posture and make an informed risk acceptance decision.

BPlan of action and milestones (POA&M)

A Plan of Action and Milestones (POA&M) details remediation efforts for identified weaknesses but is only one component of the broader authorization package, not the full basis for the AO's risk determination.

CSecurity plan (SP)

The Security Plan (SP) outlines the system's security controls and requirements but is merely one part of the comprehensive authorization package and does not provide the complete risk picture by itself.

DInterconnection security agreement (ISA)

An Interconnection Security Agreement (ISA) pertains specifically to security requirements between interconnected systems and is not the primary, overarching document for an AO's holistic risk determination of an entire information system.

Concept tested: RMF Authorization Official risk determination inputs

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Authorizing Official (AO)#Security Authorization Package (SAP)#Risk Determination#Authorization to Operate (ATO)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice