CGRC · Question #590
According to NIST SP 800-37 Rev 2 appendix F, there are several types of authorizations including all of the following, except one. Response:
The correct answer is D. Authorization decision. NIST SP 800-37 Rev 2 Appendix F outlines initial authorization, ongoing authorization, and reauthorization as types of authorization, but 'authorization decision' is the outcome or act, not a type of authorization itself.
Question
According to NIST SP 800-37 Rev 2 appendix F, there are several types of authorizations including all of the following, except one. Response:
Options
- AInitial authorization
- BOngoing authorization
- Creauthorization
- DAuthorization decision
How the community answered
(28 responses)- A7% (2)
- C4% (1)
- D89% (25)
Why each option
NIST SP 800-37 Rev 2 Appendix F outlines initial authorization, ongoing authorization, and reauthorization as types of authorization, but 'authorization decision' is the outcome or act, not a type of authorization itself.
Initial authorization is a type of authorization performed prior to a system's initial operational use.
Ongoing authorization is a type of authorization that continuously monitors and assesses the system's security posture throughout its lifecycle.
Reauthorization is a type of authorization performed when significant changes occur or at predetermined intervals to reaffirm an existing authorization.
According to NIST SP 800-37 Rev. 2, Appendix F, 'Authorization decision' is the outcome of the authorization process - the decision by an authorizing official to authorize (or not authorize) an information system for operation. It is not listed as a type of authorization alongside initial, ongoing, and reauthorization, which describe the phase or duration of the authorization.
Concept tested: Types of authorization in NIST RMF
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.