nerdexam
(ISC)2

CGRC · Question #642

Who has the primary responsibility to report the authorization decision? Response:

The correct answer is A. The Authorizing Official (AO) and Authorizing Official Designated Representative (AODR). The Authorizing Official (AO) and their Designated Representative (AODR) are primarily responsible for formally reporting the authorization decision for an information system. This decision signifies acceptance of the risk associated with operating the system.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Who has the primary responsibility to report the authorization decision? Response:

Options

  • AThe Authorizing Official (AO) and Authorizing Official Designated Representative (AODR)
  • BThe Common Control Provider (CCP) and the Information System Owner (ISO)
  • CThe authorizing official (AO) and the Information System Owner (ISO)
  • DThe Information System Owner (ISO) and Authorizing Official Designated Representative (AODR)

How the community answered

(19 responses)
  • A
    89% (17)
  • B
    5% (1)
  • C
    5% (1)

Why each option

The Authorizing Official (AO) and their Designated Representative (AODR) are primarily responsible for formally reporting the authorization decision for an information system. This decision signifies acceptance of the risk associated with operating the system.

AThe Authorizing Official (AO) and Authorizing Official Designated Representative (AODR)Correct

The Authorizing Official (AO) is ultimately accountable for the authorization decision, while the Authorizing Official Designated Representative (AODR) supports the AO in fulfilling this responsibility, including formal reporting of the decision. Together, they ensure the decision is communicated to relevant stakeholders.

BThe Common Control Provider (CCP) and the Information System Owner (ISO)

The Common Control Provider (CCP) manages shared security controls, and the Information System Owner (ISO) manages the system, but neither is primarily responsible for formally reporting the authorization decision itself.

CThe authorizing official (AO) and the Information System Owner (ISO)

While the AO makes the ultimate decision, the ISO is responsible for the system's operational security and risk management, not the formal reporting of the authorization decision.

DThe Information System Owner (ISO) and Authorizing Official Designated Representative (AODR)

The ISO manages the system and its risks, but the formal reporting of the authorization decision rests with the AO and AODR.

Concept tested: Authorization decision reporting roles

Source: https://csrc.nist.gov/glossary/term/authorizing_official_designated_representative

Topics

#Authorization Decision#Roles and Responsibilities#Authorizing Official (AO)#Authorizing Official Designated Representative (AODR)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice