nerdexam
(ISC)2

CGRC · Question #560

Significant changes to the environment of operation may trigger an event-driven authorization action which may not be limited to all of the following except one. Choose the exception. Response:

The correct answer is D. Modifications to how information, including PII, is processed. Significant changes in an information system's environment, such as facility relocation, new core missions, or updated regulations, trigger event-driven authorization actions, whereas routine modifications to information processing within existing scope typically do not.

Compliance Maintenance

Question

Significant changes to the environment of operation may trigger an event-driven authorization action which may not be limited to all of the following except one. Choose the exception. Response:

Options

  • AMoving to a new facility
  • BAdding new core missions or business functions
  • CEstablishing new/modified laws, directives, policies,or regulations
  • DModifications to how information, including PII, is processed

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    4% (2)
  • D
    92% (48)

Why each option

Significant changes in an information system's environment, such as facility relocation, new core missions, or updated regulations, trigger event-driven authorization actions, whereas routine modifications to information processing within existing scope typically do not.

AMoving to a new facility

Moving an information system to a new facility represents a significant change to its physical and environmental security controls, thus triggering an event-driven reauthorization.

BAdding new core missions or business functions

Adding new core missions or business functions fundamentally alters the system's purpose, scope, and potential impact, necessitating a re-evaluation of its authorization.

CEstablishing new/modified laws, directives, policies,or regulations

Establishing new or modified laws, directives, policies, or regulations directly impacts the system's compliance and risk posture, requiring an event-driven authorization action to ensure adherence.

DModifications to how information, including PII, is processedCorrect

Modifications to how information, including PII, is processed within the existing operational scope are usually managed through ongoing monitoring and routine updates, and generally do not trigger a complete event-driven reauthorization unless they fundamentally alter the system's risk profile or security posture in a significant, unforeseen way. The other options represent fundamental shifts in the operational environment or legal basis requiring reassessment.

Concept tested: RMF event-driven authorization triggers

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Event-Driven Authorization#Significant Change Management#NIST RMF#Authorization Boundary

Community Discussion

No community discussion yet for this question.

Full CGRC Practice