CGRC · Domain 6
System Compliance
About 14% of the exam
The Authorize step
- Assemble the package
- Analyze risk
- Determine risk
- Respond to risk
- Decide
- Report
- Package
- SSP, SAR, POA&M, executive summary
- Risk analysis
- findings weighed against mission need
- Determination
- is residual risk acceptable
- Response
- conditions, more controls, or refuse
- Decision document
- terms, conditions, authorization termination date
- Report
- decision shared with stakeholders
Authorization is a risk-based decision by one accountable official, not a checklist score
The authorization package
- SSP
- boundary and how controls are implemented
- SAR
- how well the controls actually work
- POA&M
- what remains and when it closes
- Risk assessment report
- threats, likelihood, impact, residual risk
- Executive summary
- helpful, not substantive
- Privacy plan, PIA
- for systems with PII
SSP says what is there, SAR says whether it works, POA&M says what is still broken
Authorization decisions
- ATO
- risk acceptable, operate within terms
- ATO with conditions
- operate, but actions by dates
- Common control authorization
- shared controls authorized on their own
- Denial (DATO)
- risk unacceptable, cannot be fixed
- IATT
- testing only, never mission operations
- IATO
- legacy interim, no longer in Rev 2
- Ongoing authorization
- decision kept current by monitoring
The AO and delegates
- Senior official with budget and mission authority
- Independent of the system's development
- Only the AO signs the decision
- AODR does everything else, never signs
- Multiple AOs can jointly authorize
- Consults the risk executive for tolerance
- Accountable for the accepted risk personally
Risk determination
- Residual risk versus organizational tolerance
- Mission need weighed against exposure
- Severity and realism of POA&M dates
- Inherited weaknesses from providers count
- Aggregation across interconnected systems
- Privacy risk to individuals included
- Time-limited conditions when urgent
Fifteen High findings with credible thirty-day milestones can earn conditions; findings a year out cannot
POA&M mechanics
- Weakness, source, severity
- Milestones and scheduled completion dates
- Resources required and funding status
- Point of contact accountable
- Status changes with evidence
- AO watches dates and severity most
- Reported upward on agency cadence
Reuse and reciprocity
- Reciprocity
- accept another agency's assessment evidence
- Not transferable
- receiving AO still decides
- Type authorization
- one package, many identical deployments
- Site controls
- still assessed locally for type systems
- Leveraged authorization
- build on FedRAMP provider ATO
- Stricter needs
- add controls, then accept
FedRAMP
What it is
- Standardized cloud assessment and authorization
- Do once, use many times
- Impact levels: Low, Moderate, High
- LI-SaaS tailored for low-risk SaaS
- Marketplace lists authorized offerings
Who does what
- 3PAO performs independent assessment
- Agency AO authorizes for agency use
- Program-level authorizations reused by all
- Provider delivers continuous monitoring
- Agency consumes ConMon deliverables
Agency duties remain
- Customer responsibility matrix implemented
- Own ATO for the agency's use
- Monitor provider posture over time
- Reassess boundary after migration
A FedRAMP authorization lets you inherit, not abdicate: your AO still signs for your use of the service
Ongoing versus time-driven
- Time-driven: reauthorize on a fixed date
- Event-driven: revisit when risk changes
- Ongoing needs a mature monitoring program
- Trigger criteria documented in advance
- OMB A-130 pushes toward ongoing
- Significant change still forces review
- Decision stays current, not static
Package consistency checks
- SSP and SAR describe the same boundary
- Inheritance sources named and current
- Provider authorization not about to expire
- Findings map to POA&M items
- Dates realistic against severity
- Categorization matches current data types
- Excluded dependencies explained
Inheritance at decision time
- Provider weakness raises every inheritor's risk
- Common control authorization is its own decision
- Inheriting system documents what it inherits
- Migration off a platform ends inheritance
- Formerly inherited controls need fresh assessment
- Facility and provider inheritance recorded separately
- Accountability traced to the source
Privacy in the decision
- PIA current and signed by SAOP
- SORN published before operating records
- Privacy findings on the same POA&M
- Risk to individuals part of residual risk
- Privacy conditions can accompany the ATO
- New PII collection triggers reauthorization review
Know the order
- SSP
- SAR
- POA&M
- Risk determination
- Decision document
- Monitor
- Plan, then assess, then remediate
- Package before determination
- Decision before operations
- Conditions with dates and consequences
Reference strip: package, decisions, roles, reuse
Package
- SSP, SAR, POA&M
- Risk assessment report
- Executive summary optional
Decisions
- ATO, ATO with conditions
- Common control authorization
- Denial of authorization
- IATT for testing only
Roles
- AO signs, AODR prepares
- Risk executive sets tolerance
- SCA reports, owner remediates
Reuse
- Reciprocity, type, leveraged
- Receiving AO always decides
- FedRAMP for cloud services
Timing
- Termination date on the decision
- Ongoing authorization with ISCM
- Event-driven reassessment triggers
Quick exam traps
- Trap: A complete package with zero findings guarantees an ATO
- Trap: The AODR may sign the decision when fully delegated
- Trap: An IATT permits limited mission operations while testing
- Trap: Reciprocity transfers the risk acceptance to the originating agency
- Trap: A FedRAMP authorization means the agency needs no ATO of its own
- Trap: Letting an ATO expire is the same as a denial
- Trap: Conditions on an ATO are advisory and need no dates
- Trap: Ongoing authorization removes the need for reauthorization after significant change
cybercertprep.com · original revision sheet written from the public body of knowledge