Under the NIST Risk Management Framework (RMF), what is the purpose of the 'Authorize' step?
-
A
A senior official formally accepts the risk of operating an information system based on the implemented controls
-
B
IT staff are authorized to begin implementing security controls on a new system
-
C
Users receive authorization credentials to access the system after security review
-
D
The organization is authorized by a regulatory body to process sensitive data