Definition

Security authorization is

the official management decision given by a senior organization official to authorize operation of an information system and to explicitly accept the risk to organization operations and assets, individuals, other organizations, and the nation based on the implementation of an agreed-upon set of security controls.[1]

References

  1. NIST Special Publication 800-37, rev. 1.

