ISC2 Governance, Risk and Compliance (CGRC) Practice Question
An information system operating under a three-year Authorization to Operate (ATO) will reach its authorization termination date in 60 days. Continuous monitoring shows that all security controls remain effective. To keep the system online without interruption, what should the system owner do next?
Compile and transmit an updated authorization package to the authorizing official to obtain a new ATO before the current one expires.
File the latest continuous monitoring results with no additional action until the system undergoes a significant change.
Ask the information system security officer to issue a six-month temporary extension of the existing ATO.
Disable non-essential services on the expiration date and continue operating under the assumption that risk is minimal.
Under NIST RMF guidance, every ATO includes a termination (expiration) date that generally may not exceed three years. Continuous monitoring data support the overall risk picture, but they do not by themselves extend the authorization. Before the termination date, the system owner must assemble an up-to-date authorization package-including the current System Security Plan, recent Security Assessment Report results, and an updated POA&M-and submit it to the authorizing official for a new risk determination. An ISSO cannot grant an extension, simply archiving monitoring results is insufficient, and operating past the termination date without formal approval is a violation of policy.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Authorization to Operate (ATO)?
Open an interactive chat with Bash
What is continuous monitoring in the RMF process?
Open an interactive chat with Bash
What documents are included in an updated authorization package?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .