Study. uk . com
  1. Home
  2. All questions
  3. Question 6

CISSP study material · question 6 of 500

An agency's authorisation for its payroll system expires every three years, and each renewal consumes a quarter of the security team's capacity while telling leadership little that is new in between. The chief information officer asks how the Risk Management Framework intends approval to be sustained instead.

  1. Through continuous monitoring that supports ongoing authorisation with current evidence
  2. Through a shortened reauthorisation cycle that repeats the full assessment every year
  3. Through an interim approval that lapses whenever a significant change is introduced
  4. Through delegation of the authorisation decision to the system owner between renewals
Show the answer

Answer: A. Through continuous monitoring that supports ongoing authorisation with current evidence

Continuous monitoring exists to support ongoing authorisation, so approval rests on current evidence rather than a fixed calendar; shortening the cycle keeps the calendar-driven model it replaces.

Source: NIST SP 800-37 Rev. 2 (NIST) — SP 800-37 Rev. 2 > Abstract

Challenge yourself on this topic → Study as cards