nerdexam
(ISC)2

CGRC · Question #590

According to NIST SP 800-37 Rev 2 appendix F, there are several types of authorizations including all of the following, except one. Response:

The correct answer is D. Authorization decision. NIST SP 800-37 Rev 2 Appendix F outlines initial authorization, ongoing authorization, and reauthorization as types of authorization, but 'authorization decision' is the outcome or act, not a type of authorization itself.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

According to NIST SP 800-37 Rev 2 appendix F, there are several types of authorizations including all of the following, except one. Response:

Options

  • AInitial authorization
  • BOngoing authorization
  • Creauthorization
  • DAuthorization decision

How the community answered

(28 responses)
  • A
    7% (2)
  • C
    4% (1)
  • D
    89% (25)

Why each option

NIST SP 800-37 Rev 2 Appendix F outlines initial authorization, ongoing authorization, and reauthorization as types of authorization, but 'authorization decision' is the outcome or act, not a type of authorization itself.

AInitial authorization

Initial authorization is a type of authorization performed prior to a system's initial operational use.

BOngoing authorization

Ongoing authorization is a type of authorization that continuously monitors and assesses the system's security posture throughout its lifecycle.

Creauthorization

Reauthorization is a type of authorization performed when significant changes occur or at predetermined intervals to reaffirm an existing authorization.

DAuthorization decisionCorrect

According to NIST SP 800-37 Rev. 2, Appendix F, 'Authorization decision' is the outcome of the authorization process - the decision by an authorizing official to authorize (or not authorize) an information system for operation. It is not listed as a type of authorization alongside initial, ongoing, and reauthorization, which describe the phase or duration of the authorization.

Concept tested: Types of authorization in NIST RMF

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#NIST SP 800-37#Authorization#Risk Management Framework#Governance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice