CGRC Authorization Process 4 — Questions and Answers
Question 1: Which element of the authorization decision communicates specific conditions the system owner must maintain for the authorization to remain valid?
- Authorization terms and conditions (Correct answer)
- POA&M milestones
- Security categorization memo
- Continuous monitoring strategy
Correct answer: Authorization terms and conditions
Authorization terms and conditions specify the constraints and requirements the system must meet to maintain its authorization status.
Question 2: What is the relationship between continuous monitoring and the authorization process under RMF?
- Continuous monitoring replaces the need for formal re-authorization entirely
- Monitoring results feed into ongoing authorization decisions and can trigger re-authorization (Correct answer)
- Continuous monitoring is only performed after authorization expires
- Monitoring is a pre-authorization activity separate from ATO maintenance
Correct answer: Monitoring results feed into ongoing authorization decisions and can trigger re-authorization
Continuous monitoring provides ongoing security status data that informs the AO's ongoing authorization decisions and can trigger re-authorization if risks change significantly.
Question 3: An organization is authorizing a system that processes both classified and unclassified data on the same network segment. The primary concern during authorization would be:
- System performance degradation
- Data spillage and inadequate boundary protections (Correct answer)
- Software licensing compliance
- User training completion rates
Correct answer: Data spillage and inadequate boundary protections
Mixed-classification environments require robust boundary controls to prevent classified data from commingling with unclassified data.
Question 4: Under the DoD Risk Management Framework (RMF), the term equivalent to NIST's 'Authorizing Official' is:
- Program Manager
- Authorizing Official (same term) (Correct answer)
- Designated Accrediting Authority (DAA)
- System Owner
Correct answer: Authorizing Official (same term)
DoD adopted NIST RMF terminology and uses 'Authorizing Official' consistent with NIST SP 800-37 (replacing the legacy DAA title).
Question 5: A system owner discovers a new critical vulnerability after receiving an ATO. What is the correct course of action?
- Wait until the next scheduled assessment to report it
- Immediately notify the AO and document it in the POA&M (Correct answer)
- Revoke the ATO and resubmit a new authorization package
- Classify the finding and restrict access to the report
Correct answer: Immediately notify the AO and document it in the POA&M
New critical vulnerabilities must be promptly reported to the AO and tracked in the POA&M to support informed ongoing authorization decisions.
Question 6: Which concept describes authorizing a system based on accumulated evidence from continuous monitoring rather than periodic point-in-time assessments?
- Adaptive authorization
- Risk-based authorization
- Ongoing Authorization (Correct answer)
- Provisional Authorization
Correct answer: Ongoing Authorization
Ongoing Authorization leverages continuous monitoring data to maintain real-time authorization status rather than relying solely on periodic reassessments.
Question 7: When two or more organizations share responsibility for a system's authorization, which authorization type applies?
- Reciprocal Authorization
- Federated Authorization
- Joint Authorization (Correct answer)
- Inherited Authorization
Correct answer: Joint Authorization
Joint Authorization applies when multiple organizations share ownership and risk acceptance responsibility for a system.
Which element of the authorization decision communicates specific conditions the system owner must maintain for the authorization to remain valid?