Study. uk . com
  1. Home
  2. All questions
  3. Question 3

CISSP study material · question 3 of 500

A shared services division publishes a hardened logging and identity stack that a dozen internal systems will inherit rather than build for themselves. Leadership asks what the authorisation decision covering that published stack must convey to the owners of the inheriting systems.

  1. A waiver releasing inheriting system owners from assessing any control received from the shared stack
  2. The residual risk each inheriting system carries once the common controls are tailored to its environment
  3. The provider's monitoring results, which stand in place of the authorisation decisions of inheriting systems
  4. The impact level of systems the common controls can support, plus documentation and tooling for inheriting owners
Show the answer

Answer: D. The impact level of systems the common controls can support, plus documentation and tooling for inheriting owners

A common control authorization states the system impact level the controls support and obliges the provider to supply documentation and tooling; inheriting owners keep their own authorisation decisions.

Source: NIST SP 800-37 Rev. 2 (NIST) — SP 800-37 Rev. 2 > Appendix F, Authorization Decisions (Common Control Authorization)

Challenge yourself on this topic → Study as cards