- Home
- All questions
- Question 574
CISM study material · question 574 of 1000
Which definition of security accreditation does NIST give?
Show the answer
Answer: C. The official management decision by a senior official authorising a system to operate and explicitly accepting the risk, based on an agreed set of controls
SP 800-100 defines accreditation as a senior official's formal management decision: operation is authorised and the risk explicitly accepted, resting on an agreed set of implemented controls.
Source: NIST SP 800-100 (NIST) — Sec. 14.1 CM in the System Development Life Cycle