nerdexam
(ISC)2

CGRC · Question #559

What is the objective of the Security Accreditation Decision task? Response:

The correct answer is A. To determine whether the agency-level risk is acceptable or not.. The objective of the Security Accreditation Decision task is for the Authorizing Official to determine whether the agency-level risk posed by operating an information system is acceptable.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What is the objective of the Security Accreditation Decision task? Response:

Options

  • ATo determine whether the agency-level risk is acceptable or not.
  • BTo make an accreditation decision
  • CTo accredit the information system
  • DTo approve revisions of NIACAP

How the community answered

(44 responses)
  • A
    93% (41)
  • C
    5% (2)
  • D
    2% (1)

Why each option

The objective of the Security Accreditation Decision task is for the Authorizing Official to determine whether the agency-level risk posed by operating an information system is acceptable.

ATo determine whether the agency-level risk is acceptable or not.Correct

The Security Accreditation Decision, performed by the Authorizing Official, is fundamentally a risk acceptance decision. The AO reviews the complete security authorization package to evaluate the system's residual risk and formally decide if that level of risk is acceptable for the organization to proceed with system operation.

BTo make an accreditation decision

While the task involves making "an accreditation decision," this choice is too vague and does not specify the underlying objective of evaluating and accepting risk.

CTo accredit the information system

"To accredit the information system" is the outcome of a positive accreditation decision, not the objective of the decision-making process itself.

DTo approve revisions of NIACAP

"To approve revisions of NIACAP" is unrelated to the accreditation decision for a specific information system; NIACAP refers to a broader certification and accreditation process framework.

Concept tested: RMF Security Accreditation Decision objective

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Security Accreditation Decision#Risk Acceptance#RMF#Authorization to Operate (ATO)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice