CGRC · Question #557
What key information is used by the authorizing official (AO) to assist with the risk determination of an information system (IS)? Response:
The correct answer is A. Security authorization package (SAP). The Authorizing Official (AO) relies on the comprehensive Security Authorization Package (SAP) as key information to assist in making an informed risk determination for an information system.
Question
What key information is used by the authorizing official (AO) to assist with the risk determination of an information system (IS)? Response:
Options
- ASecurity authorization package (SAP)
- BPlan of action and milestones (POA&M)
- CSecurity plan (SP)
- DInterconnection security agreement (ISA)
How the community answered
(34 responses)- A94% (32)
- C3% (1)
- D3% (1)
Why each option
The Authorizing Official (AO) relies on the comprehensive Security Authorization Package (SAP) as key information to assist in making an informed risk determination for an information system.
The Security Authorization Package (SAP) is a complete collection of documentation, including the security plan, security assessment report, and plan of action and milestones (POA&M), which provides the AO with all necessary evidence to evaluate the system's security posture and make an informed risk acceptance decision.
A Plan of Action and Milestones (POA&M) details remediation efforts for identified weaknesses but is only one component of the broader authorization package, not the full basis for the AO's risk determination.
The Security Plan (SP) outlines the system's security controls and requirements but is merely one part of the comprehensive authorization package and does not provide the complete risk picture by itself.
An Interconnection Security Agreement (ISA) pertains specifically to security requirements between interconnected systems and is not the primary, overarching document for an AO's holistic risk determination of an entire information system.
Concept tested: RMF Authorization Official risk determination inputs
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.