CGRC · Question #559
What is the objective of the Security Accreditation Decision task? Response:
The correct answer is A. To determine whether the agency-level risk is acceptable or not.. The objective of the Security Accreditation Decision task is for the Authorizing Official to determine whether the agency-level risk posed by operating an information system is acceptable.
Question
What is the objective of the Security Accreditation Decision task? Response:
Options
- ATo determine whether the agency-level risk is acceptable or not.
- BTo make an accreditation decision
- CTo accredit the information system
- DTo approve revisions of NIACAP
How the community answered
(44 responses)- A93% (41)
- C5% (2)
- D2% (1)
Why each option
The objective of the Security Accreditation Decision task is for the Authorizing Official to determine whether the agency-level risk posed by operating an information system is acceptable.
The Security Accreditation Decision, performed by the Authorizing Official, is fundamentally a risk acceptance decision. The AO reviews the complete security authorization package to evaluate the system's residual risk and formally decide if that level of risk is acceptable for the organization to proceed with system operation.
While the task involves making "an accreditation decision," this choice is too vague and does not specify the underlying objective of evaluating and accepting risk.
"To accredit the information system" is the outcome of a positive accreditation decision, not the objective of the decision-making process itself.
"To approve revisions of NIACAP" is unrelated to the accreditation decision for a specific information system; NIACAP refers to a broader certification and accreditation process framework.
Concept tested: RMF Security Accreditation Decision objective
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.