nerdexam
(ISC)2

CGRC · Question #602

An authorization approach where multiple organizational officials either from the same organization or different organizations, have a shared interest in authorizing a system is known as: Response:

The correct answer is C. Joint authorization. Joint authorization is an approach where multiple organizational officials collaborate to authorize a system, especially when they share an interest in its operation. This method ensures shared responsibility and oversight for systems affecting multiple stakeholders.

Selection and Approval of Framework, Security, and Privacy Controls

Question

An authorization approach where multiple organizational officials either from the same organization or different organizations, have a shared interest in authorizing a system is known as:

Response:

Options

  • ASingle authorization
  • BSite authorization
  • CJoint authorization
  • DTraditional authorization

How the community answered

(58 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    93% (54)
  • D
    2% (1)

Why each option

Joint authorization is an approach where multiple organizational officials collaborate to authorize a system, especially when they share an interest in its operation. This method ensures shared responsibility and oversight for systems affecting multiple stakeholders.

ASingle authorization

Single authorization implies only one official is responsible for the authorization, which contradicts the 'multiple organizational officials' aspect of the question.

BSite authorization

Site authorization refers to authorization based on the physical location or operational site, not necessarily the number or type of authorizing officials.

CJoint authorizationCorrect

Joint authorization specifically refers to the scenario where multiple officials, potentially from different entities, collectively approve or authorize an information system, reflecting shared interest and accountability. This is common for systems that cross organizational boundaries or serve multiple missions.

DTraditional authorization

Traditional authorization is a vague term and does not specifically define the involvement of multiple officials as described in the question.

Concept tested: Types of system authorization processes

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Joint authorization#System authorization#Authorization approaches#RMF Authorize step

Community Discussion

No community discussion yet for this question.

Full CGRC Practice