CGRC Authorization Process 5 — Questions and Answers
Question 1: Which risk response option is the AO implicitly choosing when issuing an ATO despite known residual risks?
- Risk avoidance
- Risk transfer
- Risk acceptance (Correct answer)
- Risk mitigation
Correct answer: Risk acceptance
By issuing an ATO knowing that residual risks exist, the AO is formally accepting those risks on behalf of the organization.
Question 2: What distinguishes a 'common control' from a 'system-specific control' in the context of authorization?
- Common controls are assessed more rigorously
- Common controls are inherited by multiple systems and authorized separately (Correct answer)
- System-specific controls apply across the entire organization
- Common controls are always implemented in hardware
Correct answer: Common controls are inherited by multiple systems and authorized separately
Common controls are managed and authorized by a common control provider and can be inherited by multiple systems, reducing redundant implementation effort.
Question 3: An AO is reviewing an authorization package and finds that most HIGH-impact controls are satisfied, but two critical controls have open POA&M items. The BEST course of action is:
- Automatically deny authorization until all findings are closed
- Issue an ATO with terms requiring timely remediation of the open items (Correct answer)
- Remove the controls from scope to clear the package
- Transfer the system to a lower-impact categorization
Correct answer: Issue an ATO with terms requiring timely remediation of the open items
An AO may issue an ATO with conditions requiring remediation of open items by specified milestones, balancing operational need against residual risk.
Question 4: Which activity marks the formal beginning of the Authorize step in the NIST RMF lifecycle?
- Submission of the authorization package to the AO (Correct answer)
- Completion of the security categorization
- Selection of the security control baseline
- Initiation of the security assessment
Correct answer: Submission of the authorization package to the AO
The Authorize step formally begins when the complete authorization package (SSP, SAR, POA&M) is submitted to the Authorizing Official for review.
Question 5: A third-party assessment organization (3PAO) conducts the security assessment for a cloud system. This primarily strengthens the authorization process by:
- Reducing the cost of the assessment
- Providing independence and objectivity in control evaluation (Correct answer)
- Replacing the need for an AO authorization decision
- Eliminating the requirement for a POA&M
Correct answer: Providing independence and objectivity in control evaluation
3PAOs provide independent, objective assessment of security controls, increasing confidence in the SAR findings used by the AO.
Question 6: What is the key difference between an Authorization to Operate (ATO) and an Authorization to Use (ATU)?
- An ATU is issued for classified systems only
- An ATU authorizes an organization to use an externally operated system it does not own (Correct answer)
- An ATO requires more controls than an ATU
- An ATU is a temporary authorization while an ATO is permanent
Correct answer: An ATU authorizes an organization to use an externally operated system it does not own
An Authorization to Use (ATU) allows an organization to use and rely on a system or service operated by another organization rather than operating it themselves.
Question 7: Which risk acceptance criterion would most likely cause an AO to DENY authorization despite strong system security controls?
- The system processes only publicly available information
- The system's mission criticality does not justify the residual risk level (Correct answer)
- The system was assessed by an internal team
- The system has an existing interim ATO
Correct answer: The system's mission criticality does not justify the residual risk level
If the residual risk outweighs the mission value or the organization's risk tolerance, an AO may deny authorization even when many controls are effective.
Which risk response option is the AO implicitly choosing when issuing an ATO despite known residual risks?