ISC2 Governance, Risk and Compliance (CGRC) Practice Question
You have compiled the System Security Plan, Security Assessment Report, and POA&M for a newly deployed financial application. Before transmitting the authorization decision document to stakeholders, which element must be present for the decision (ATO, Denial, or other) to be legally binding on the organization?
The authorizing official's signed statement formally accepting the system's residual risk and granting (or denying) authority to operate
A memorandum from the system owner requesting approval to place the system into production
A written concurrence from the organization's risk executive (function) supporting the authorization
A schedule of controls to be reassessed annually, endorsed by the information system security officer
NIST SP 800-37 specifies that an authorization decision document is not valid unless the authorizing official (AO) formally accepts the system's documented residual risk and signs the decision letter. The AO's signature demonstrates organizational commitment and provides the legal authority to operate under stated terms and conditions. Other items-such as annual assessment schedules, the system owner's request, or risk-executive concurrence-may accompany the package but are not mandatory components that make the decision enforceable.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is residual risk in system authorization?
Open an interactive chat with Bash
What is the role of the Authorizing Official (AO) in the authorization process?
Open an interactive chat with Bash
What is NIST SP 800-37 and why is it important?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .