NIST SP 800-37
RMF Step 5 - Authorize

NIST SP 800-37 NISTSP37-6: RMF Authorize Step: Authorisation Decision and ATO

Execute the Authorize step per NIST SP 800-37 Rev 2 Chapter 3 Step 6. The Authorising Official (AO) reviews the authorisation package (SSPP + SAR + POAM + executive summary) and makes one of three decisions: (a) Authorisation to Operate (ATO) granted (with or without conditions and risk acceptance), (b) Common Control Authorisation, or (c) Denial of Authorisation. Tasks include (R-1) assemble authorisation package, (R-2) risk determination by AO informed by Risk Executive Function and risk assessment outputs (NIST SP 800-30), (R-3) risk response determination (accept + avoid + mitigate + share + transfer), (R-4) authorisation decision and ATO letter with conditions, (R-5) authorisation reporting to senior leadership + risk owners + system stakeholders. Ongoing Authorisation Maintenance must keep ATO current as risk posture evolves.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.