Execute the Authorize step per NIST SP 800-37 Rev 2 Chapter 3 Step 6. The Authorising Official (AO) reviews the authorisation package (SSPP + SAR + POAM + executive summary) and makes one of three decisions: (a) Authorisation to Operate (ATO) granted (with or without conditions and risk acceptance), (b) Common Control Authorisation, or (c) Denial of Authorisation. Tasks include (R-1) assemble authorisation package, (R-2) risk determination by AO informed by Risk Executive Function and risk assessment outputs (NIST SP 800-30), (R-3) risk response determination (accept + avoid + mitigate + share + transfer), (R-4) authorisation decision and ATO letter with conditions, (R-5) authorisation reporting to senior leadership + risk owners + system stakeholders. Ongoing Authorisation Maintenance must keep ATO current as risk posture evolves.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.