Study. uk . com
  1. Home
  2. All questions
  3. Question 574

CISM study material · question 574 of 1000

Which definition of security accreditation does NIST give?

  1. The formal registration of a system in the organisation's own inventory of systems, which fixes its identifier and records the business owner who is accountable for operating it from day to day
  2. The independent audit of a system against a published standard, carried out by an accredited body which then issues a certificate on the satisfactory completion of it
  3. The official management decision by a senior official authorising a system to operate and explicitly accepting the risk, based on an agreed set of controls
  4. The technical verification that the selected controls have been correctly implemented on the system, carried out by an assessor before it is allowed to enter operation
Show the answer

Answer: C. The official management decision by a senior official authorising a system to operate and explicitly accepting the risk, based on an agreed set of controls

SP 800-100 defines accreditation as a senior official's formal management decision: operation is authorised and the risk explicitly accepted, resting on an agreed set of implemented controls.

Source: NIST SP 800-100 (NIST) — Sec. 14.1 CM in the System Development Life Cycle

Challenge yourself on this topic → Study as cards