nerdexam
(ISC)2

CGRC · Question #604

Who is the official with the authority to formally assume responsibility for operating an IS at an acceptable level of risk to agency operations (including mission, functions, image, or reputation)…

The correct answer is A. Authorizing Official (AO). The Authorizing Official (AO) is the individual empowered to formally accept the operational risk for an information system after assessing its security posture. This role is crucial in the Risk Management Framework (RMF), as the AO grants the Authorization to Operate (ATO).

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Who is the official with the authority to formally assume responsibility for operating an IS at an acceptable level of risk to agency operations (including mission, functions, image, or reputation), agency assets, or individuals. Synonymous with Accreditation Authority. Response:

Options

  • AAuthorizing Official (AO)
  • BInformation Security Architect (ISA)
  • CInformation System Owner (ISO)
  • DChief Information Officer (CIO)

How the community answered

(26 responses)
  • A
    88% (23)
  • B
    4% (1)
  • C
    8% (2)

Why each option

The Authorizing Official (AO) is the individual empowered to formally accept the operational risk for an information system after assessing its security posture. This role is crucial in the Risk Management Framework (RMF), as the AO grants the Authorization to Operate (ATO).

AAuthorizing Official (AO)Correct

The Authorizing Official (AO) is precisely the individual defined by NIST and other frameworks as having the authority to accept the risk associated with an information system and grant an Authorization to Operate (ATO). The question explicitly states 'formally assume responsibility for operating an IS at an acceptable level of risk' and mentions 'Synonymous with Accreditation Authority,' which are key characteristics of an AO.

BInformation Security Architect (ISA)

An Information Security Architect designs security solutions but does not typically hold the formal authority to accept overall operational risk for a system.

CInformation System Owner (ISO)

An Information System Owner is responsible for the system throughout its lifecycle but does not typically have the ultimate authority to formally accept the operational risk for the agency.

DChief Information Officer (CIO)

A Chief Information Officer (CIO) is a senior executive responsible for an organization's IT strategy and operations, but while they may oversee the RMF process, the specific role of formally accepting risk for an individual system is usually delegated to an AO.

Concept tested: Role of Authorizing Official (AO)

Source: https://csrc.nist.gov/glossary/term/authorizing_official

Topics

#Authorizing Official (AO)#Risk Acceptance#Authorization to Operate (ATO)#Accreditation Authority

Community Discussion

No community discussion yet for this question.

Full CGRC Practice