nerdexam
(ISC)2

CGRC · Question #70

Interrelationships of system authorization processes. Response:

The correct answer is A. 1. System Security Authorization Project Planning. This question asks for a critical initial component related to managing the interrelationships within system authorization processes.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Interrelationships of system authorization processes. Response:

Options

  • A
    1. System Security Authorization Project Planning.
  • B
    1. System Security Authorization Project Planning.
  • C
    1. Coordinate Security for Interconnected Systems.
  • D
    1. Conduct Certification Testing

How the community answered

(31 responses)
  • A
    87% (27)
  • B
    3% (1)
  • C
    6% (2)
  • D
    3% (1)

Why each option

This question asks for a critical initial component related to managing the interrelationships within system authorization processes.

A1. System Security Authorization Project Planning.Correct

System Security Authorization Project Planning is a critical initial step in the overall authorization process, particularly when dealing with system interrelationships, as it sets the scope, resources, and coordination efforts for ensuring security across interconnected systems. Proper planning is essential to manage the complexities of authorization.

B1. System Security Authorization Project Planning.

This choice is a duplicate of A, which is the correct answer.

C1. Coordinate Security for Interconnected Systems.

Coordinate Security for Interconnected Systems is an activity or an objective within the authorization process, but not necessarily the overarching "Project Planning" phase itself.

D1. Conduct Certification Testing

Conduct Certification Testing is a later stage in the authorization process (the "Certification" part), which follows planning and implementation, rather than describing the initial interrelationships or planning for them.

Concept tested: System authorization process planning (NIST RMF)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#System Authorization#Project Planning#Risk Management Framework (RMF)#Compliance Process

Community Discussion

No community discussion yet for this question.

Full CGRC Practice