nerdexam
(ISC)2

CGRC · Question #635

When an authorizing official (AO) submits the security authorization decision, what responses should the information system owner (ISO) expect to receive? Response:

The correct answer is A. Authorized to operate (ATO) or denial authorization to operate (DATO), the conditions for the. The information system owner should expect to receive a final authorization decision, either Authorized to Operate (ATO) or Denial Authorization to Operate (DATO), along with the specific conditions associated with that decision.

System Compliance

Question

When an authorizing official (AO) submits the security authorization decision, what responses should the information system owner (ISO) expect to receive? Response:

Options

  • AAuthorized to operate (ATO) or denial authorization to operate (DATO), the conditions for the
  • BAuthorized to Operate (ATO) or Denial Authorization to Operate (DATO), the list of security
  • CAuthorized to operate (ATO) or denial authorization to operate (DATO), and the conditions for the
  • DA plan of action and milestones (POA&M), the conditions for the authorization placed on the

How the community answered

(21 responses)
  • A
    86% (18)
  • B
    10% (2)
  • C
    5% (1)

Why each option

The information system owner should expect to receive a final authorization decision, either Authorized to Operate (ATO) or Denial Authorization to Operate (DATO), along with the specific conditions associated with that decision.

AAuthorized to operate (ATO) or denial authorization to operate (DATO), the conditions for theCorrect

The Authorizing Official (AO) makes the final risk-based decision to authorize an information system to operate (ATO) or deny authorization to operate (DATO). This decision is always accompanied by any specific terms and conditions under which the system is authorized to operate, or the reasons for denial, which the ISO must understand and adhere to.

BAuthorized to Operate (ATO) or Denial Authorization to Operate (DATO), the list of security

While security controls are assessed, the list of security controls themselves is part of the supporting documentation, not the primary decision response expected from the AO.

CAuthorized to operate (ATO) or denial authorization to operate (DATO), and the conditions for the

This choice is almost identical to A, but the text is cut off and A represents the most complete standard phrasing.

DA plan of action and milestones (POA&M), the conditions for the authorization placed on the

A Plan of Action and Milestones (POA&M) is a document created before or concurrent with an ATO to address identified weaknesses, but it is not the authorization decision itself received from the AO.

Concept tested: Authorization to Operate (ATO) process

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Authorization to Operate (ATO)#Denial Authorization to Operate (DATO)#Risk Management Framework (RMF)#Authorizing Official (AO)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice