QuestionQ332

Secure Software Requirements

Which person within an organization is responsible for accepting or rejecting a system’s residual risk?

  • A Information Systems Security Officer (ISSO)
  • B Designated Approving Authority (DAA)
  • C System Owner
  • D Chief Information Security Officer (CISO)
Explanation

The Designated Approving Authority (DAA) is the senior official authorized to decide whether a system may operate at an acceptable level of risk, including formally accepting its residual risk. NIST identifies the DAA as synonymous with the authorizing official and describes authorization as the decision that explicitly accepts residual risk.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!