CGRC · Question #615
The authorization decision may carry restrictions on system operation and caveats that must be followed to maintain the authorization, and other information as determined by the organization…
The correct answer is D. all of the above. The authorization decision encompasses various critical pieces of information, including specific terms and conditions for maintaining authorization, events that would trigger a review, and the impact level supported by any common controls. These details ensure comprehensive…
Question
The authorization decision may carry restrictions on system operation and caveats that must be followed to maintain the authorization, and other information as determined by the organization including:
Response:
Options
- ATerms and conditions for the authorization
- BEvents that may trigger a review of the authorization decision
- CThe impact level supported by common controls
- Dall of the above
How the community answered
(34 responses)- A3% (1)
- B3% (1)
- D94% (32)
Why each option
The authorization decision encompasses various critical pieces of information, including specific terms and conditions for maintaining authorization, events that would trigger a review, and the impact level supported by any common controls. These details ensure comprehensive risk management and compliance throughout the system's lifecycle.
While terms and conditions are included, this choice is not comprehensive enough as it misses other important elements of an authorization decision.
While triggers for review are included, this choice is not comprehensive enough as it misses other important elements of an authorization decision.
While the impact level supported by common controls is included, this choice is not comprehensive enough as it misses other important elements of an authorization decision.
The authorization decision is a comprehensive document that encompasses terms and conditions for maintaining the authorization, specific events that would necessitate a review of the decision, and clarity on the impact level supported by any common controls leveraged by the system. All these components are vital for ensuring ongoing security posture and risk management.
Concept tested: NIST RMF Authorization Decision contents
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.