ISC2 Governance, Risk and Compliance (CGRC) Practice Question
An Authorizing Official (AO) decides to deny an Authorization to Operate (ATO) after reviewing the assessment results for a new human-resources SaaS platform. According to NIST RMF guidance, which element must still be documented in the formal authorization decision that is delivered to the system owner?
A written rationale describing the residual risks and deficiencies that led to the denial
An interim ATO expiration date set no later than six months from issuance
A statement granting limited processing authority for mission-critical data only
Confirmation that every weakness listed in the POA&M has been fully remediated
The authorization decision document always records the AO's risk determination and the reasoning that supports that determination. When the decision is a denial, the AO must still provide the rationale that identifies the unaccepted residual risks or control deficiencies so the system owner understands why operation is prohibited and what must be addressed. An interim ATO expiration date or limited processing statement apply only when some form of authorization is granted, and confirmation that all POA&M items are closed would contradict a denial.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is residual risk in the context of NIST RMF?
Open an interactive chat with Bash
What is a POA&M, and how is it used in the authorization process?
Open an interactive chat with Bash
Who is the Authorizing Official (AO), and what is their role in the RMF process?
Open an interactive chat with Bash
What is residual risk in the context of NIST RMF?
Open an interactive chat with Bash
What is the formal Authorization to Operate (ATO) process in NIST RMF?
Open an interactive chat with Bash
What is the purpose of a POA&M in NIST RMF?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .