CGRC Authorization Process 2 — Questions and Answers
Question 1: Which document formally grants a system the authority to operate and is signed by a senior official?
- System Security Plan (SSP)
- Authorization to Operate (ATO) (Correct answer)
- Plan of Action and Milestones (POA&M)
- Security Assessment Report (SAR)
Correct answer: Authorization to Operate (ATO)
An Authorization to Operate (ATO) is the formal decision document signed by an Authorizing Official granting a system permission to operate.
Question 2: What role is ultimately accountable for accepting residual risk and issuing an authorization decision under NIST RMF?
- Information System Security Officer (ISSO)
- System Owner
- Authorizing Official (AO) (Correct answer)
- Chief Information Officer (CIO)
Correct answer: Authorizing Official (AO)
The Authorizing Official (AO) is the senior executive who accepts residual risk and signs the authorization decision.
Question 3: A system is granted permission to operate for 90 days while remediation of high-risk findings is completed. This is best described as:
- Full Authorization to Operate
- Denial of Authorization
- Interim Authorization to Operate (IATO) (Correct answer)
- Conditional ATO
Correct answer: Interim Authorization to Operate (IATO)
An Interim Authorization to Operate (IATO) allows temporary operation while significant security issues are being remediated.
Question 4: Which of the following is NOT typically included in an authorization package submitted to the Authorizing Official?
- System Security Plan (SSP)
- Security Assessment Report (SAR)
- Vendor contract for hardware procurement (Correct answer)
- Plan of Action and Milestones (POA&M)
Correct answer: Vendor contract for hardware procurement
Authorization packages consist of the SSP, SAR, and POA&M; vendor procurement contracts are not part of the authorization package.
Question 5: Under NIST SP 800-37, what triggers the need to re-authorize a system before its ATO expiration date?
- Routine patch application
- Significant change that affects the security posture (Correct answer)
- Addition of a new user account
- Annual security awareness training completion
Correct answer: Significant change that affects the security posture
Significant changes that impact a system's security posture require re-authorization even before the current ATO expires.
Question 6: The Security Assessment Report (SAR) is primarily used by the Authorizing Official to:
- Define security control requirements
- Understand the results of control testing and residual risks (Correct answer)
- Assign system categorization levels
- Develop the system security plan
Correct answer: Understand the results of control testing and residual risks
The SAR summarizes assessment findings and residual risks, giving the AO the information needed to make an informed authorization decision.
Question 7: Which NIST publication provides the primary framework for the authorization process in federal information systems?
- NIST SP 800-53
- NIST SP 800-37 (Correct answer)
- NIST SP 800-171
- NIST SP 800-30
Correct answer: NIST SP 800-37
NIST SP 800-37 defines the Risk Management Framework (RMF), including the Authorize step and its requirements.
Which document formally grants a system the authority to operate and is signed by a senior official?