CGRC · Question #560
Significant changes to the environment of operation may trigger an event-driven authorization action which may not be limited to all of the following except one. Choose the exception. Response:
The correct answer is D. Modifications to how information, including PII, is processed. Significant changes in an information system's environment, such as facility relocation, new core missions, or updated regulations, trigger event-driven authorization actions, whereas routine modifications to information processing within existing scope typically do not.
Question
Significant changes to the environment of operation may trigger an event-driven authorization action which may not be limited to all of the following except one. Choose the exception. Response:
Options
- AMoving to a new facility
- BAdding new core missions or business functions
- CEstablishing new/modified laws, directives, policies,or regulations
- DModifications to how information, including PII, is processed
How the community answered
(52 responses)- A2% (1)
- B2% (1)
- C4% (2)
- D92% (48)
Why each option
Significant changes in an information system's environment, such as facility relocation, new core missions, or updated regulations, trigger event-driven authorization actions, whereas routine modifications to information processing within existing scope typically do not.
Moving an information system to a new facility represents a significant change to its physical and environmental security controls, thus triggering an event-driven reauthorization.
Adding new core missions or business functions fundamentally alters the system's purpose, scope, and potential impact, necessitating a re-evaluation of its authorization.
Establishing new or modified laws, directives, policies, or regulations directly impacts the system's compliance and risk posture, requiring an event-driven authorization action to ensure adherence.
Modifications to how information, including PII, is processed within the existing operational scope are usually managed through ongoing monitoring and routine updates, and generally do not trigger a complete event-driven reauthorization unless they fundamentally alter the system's risk profile or security posture in a significant, unforeseen way. The other options represent fundamental shifts in the operational environment or legal basis requiring reassessment.
Concept tested: RMF event-driven authorization triggers
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.