CGRC · Question #635
When an authorizing official (AO) submits the security authorization decision, what responses should the information system owner (ISO) expect to receive? Response:
The correct answer is A. Authorized to operate (ATO) or denial authorization to operate (DATO), the conditions for the. The information system owner should expect to receive a final authorization decision, either Authorized to Operate (ATO) or Denial Authorization to Operate (DATO), along with the specific conditions associated with that decision.
Question
When an authorizing official (AO) submits the security authorization decision, what responses should the information system owner (ISO) expect to receive? Response:
Options
- AAuthorized to operate (ATO) or denial authorization to operate (DATO), the conditions for the
- BAuthorized to Operate (ATO) or Denial Authorization to Operate (DATO), the list of security
- CAuthorized to operate (ATO) or denial authorization to operate (DATO), and the conditions for the
- DA plan of action and milestones (POA&M), the conditions for the authorization placed on the
How the community answered
(21 responses)- A86% (18)
- B10% (2)
- C5% (1)
Why each option
The information system owner should expect to receive a final authorization decision, either Authorized to Operate (ATO) or Denial Authorization to Operate (DATO), along with the specific conditions associated with that decision.
The Authorizing Official (AO) makes the final risk-based decision to authorize an information system to operate (ATO) or deny authorization to operate (DATO). This decision is always accompanied by any specific terms and conditions under which the system is authorized to operate, or the reasons for denial, which the ISO must understand and adhere to.
While security controls are assessed, the list of security controls themselves is part of the supporting documentation, not the primary decision response expected from the AO.
This choice is almost identical to A, but the text is cut off and A represents the most complete standard phrasing.
A Plan of Action and Milestones (POA&M) is a document created before or concurrent with an ATO to address identified weaknesses, but it is not the authorization decision itself received from the AO.
Concept tested: Authorization to Operate (ATO) process
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.