nerdexam
(ISC)2

CGRC · Question #95

Which of the following is an official authorization decision that is focused on specific controls implemented in a defined environment of operation to support one or more systems residing within the…

The correct answer is B. Facility authorization. A facility authorization is an official decision that permits one or more information systems to operate within a specific environment based on the assessment of its implemented security controls.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following is an official authorization decision that is focused on specific controls implemented in a defined environment of operation to support one or more systems residing within the environment? Response:

Options

  • AAuthority to test
  • BFacility authorization
  • CType authorization
  • DJoint authorization

How the community answered

(24 responses)
  • B
    88% (21)
  • C
    8% (2)
  • D
    4% (1)

Why each option

A facility authorization is an official decision that permits one or more information systems to operate within a specific environment based on the assessment of its implemented security controls.

AAuthority to test

Authority to test (ATT) is a precursor to actual testing, granting permission to perform assessments, not an operational authorization decision.

BFacility authorizationCorrect

A facility authorization, also known as site authorization, is an official decision that grants approval for one or more information systems to operate within a specific environment, such as a data center or network segment. This authorization is based on the assessment of shared security controls implemented in that environment, supporting the systems residing within it.

CType authorization

Type authorization (or product authorization) applies to a generic system or product that can be deployed in various environments, not necessarily tied to a specific operational environment with implemented controls.

DJoint authorization

Joint authorization refers to an authorization granted by multiple authorizing officials, often for systems spanning multiple organizations, and is a type of authorization process rather than the authorization of a specific facility or environment itself.

Concept tested: Types of security authorizations

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Authorization decisions#Facility authorization#Risk Management Framework (RMF)#Common controls

Community Discussion

No community discussion yet for this question.

Full CGRC Practice