MLchartDataset catalogue

security authorization (to operate)

Term · Cybersecurity · MLC-T-CYB-003783

1. The official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.

2. See authorization to operate (ATO).

3. See Authorization (to operate).

4. Official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls. Authorization also applies to common controls inherited by agency information systems. Note 1: The system is authorized to operate for a specified period in accordance with terms and conditions established by the authorizing official. Note 2: Formerly known as "approval to operate." Term was replaced in the risk management framework in 2010.

5. The official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls and privacy controls.

Table 1. Record
IdentifierMLC-T-CYB-003783
FieldCybersecurity
SynonymsAuthorization (to operate); authorization to operate
ReferencesCNSSI 4009-2015 from NIST SP 800-53 Rev. 4, NIST SP 800-53A Rev. 1, NIST SP 800-37 Rev. 1; CNSSI 4009-2015 from NIST SP 800-37 Rev. 1; NIST SP 800-30 Rev. 1; NIST SP 800-39; NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-53 Rev. 5; CNSSI 4009-2022 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 4 [Superseded] from NIST SP 800-37 (Adapted); NIST CSRC Glossary
Record as JSON
{
  "id": "MLC-T-CYB-003783",
  "term": "security authorization (to operate)",
  "field": "Cybersecurity",
  "definition": "1. The official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.\n\n2. See authorization to operate (ATO).\n\n3. See Authorization (to operate).\n\n4. Official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls. Authorization also applies to common controls inherited by agency information systems. Note 1: The system is authorized to operate for a specified period in accordance with terms and conditions established by the authorizing official. Note 2: Formerly known as \"approval to operate.\" Term was replaced in the risk management framework in 2010.\n\n5. The official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls and privacy controls.",
  "synonyms": [
    "Authorization (to operate)",
    "authorization to operate"
  ],
  "references": [
    "CNSSI 4009-2015 from NIST SP 800-53 Rev. 4, NIST SP 800-53A Rev. 1, NIST SP 800-37 Rev. 1",
    "CNSSI 4009-2015 from NIST SP 800-37 Rev. 1",
    "NIST SP 800-30 Rev. 1; NIST SP 800-39",
    "NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-53 Rev. 5; CNSSI 4009-2022 from OMB Circular A-130 (2016)",
    "NIST SP 800-53A Rev. 4 [Superseded] from NIST SP 800-37 (Adapted)",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/security-authorization-to-operate/"
}

Record 3,783 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.