- Home
- All questions
- Question 1
CISSP study material · question 1 of 500
A regional insurer is finishing an authorisation package for a new claims platform. Assessors have documented three moderate findings, the system owner has drafted mitigation plans, and the chief information security officer wants the programme manager to sign off so the launch date holds. Who may formally accept the residual risk of operating the platform?
Show the answer
Answer: A. The authorizing official, because accepting residual risk is a decision that may be delegated to no one
Residual risk acceptance rests solely with the authorizing official and is non-delegable; the system owner assembles the package and assessors report findings, but neither may sign risk away.
Source: NIST SP 800-37 Rev. 2 (NIST) — SP 800-37 Rev. 2 > Chapter 3, Section 3.6, Tasks R-3 and R-4