Study. uk . com
  1. Home
  2. All questions
  3. Question 1

CISSP study material · question 1 of 500

A regional insurer is finishing an authorisation package for a new claims platform. Assessors have documented three moderate findings, the system owner has drafted mitigation plans, and the chief information security officer wants the programme manager to sign off so the launch date holds. Who may formally accept the residual risk of operating the platform?

  1. The authorizing official, because accepting residual risk is a decision that may be delegated to no one
  2. The programme manager, because delivery schedule and budget accountability sit with that role
  3. The security control assessor, because they produced the findings that describe the residual risk
  4. The system owner, because they assembled the authorization package and operate the platform daily
Show the answer

Answer: A. The authorizing official, because accepting residual risk is a decision that may be delegated to no one

Residual risk acceptance rests solely with the authorizing official and is non-delegable; the system owner assembles the package and assessors report findings, but neither may sign risk away.

Source: NIST SP 800-37 Rev. 2 (NIST) — SP 800-37 Rev. 2 > Chapter 3, Section 3.6, Tasks R-3 and R-4

Challenge yourself on this topic → Study as cards