6.6 Documenting and Communicating the Compliance Decision
Key Takeaways
- The authorization decision document records the decision, its terms and conditions, the authorization duration or ongoing-authorization basis, and an explicit residual risk statement.
- A decision that is made but not communicated has no operational effect, because the parties who must act on it do not know it exists.
- Notification must reach every system that inherits controls from the authorized system and every interconnection partner whose risk posture depends on it.
- A denial of authorization requires the same formal documentation and communication rigor as an approval, including explicit direction on the system's disposition.
- The decision triggers concrete downstream actions — inventory updates, activation of continuous monitoring, and the start of the authorization clock.
Documenting and Communicating the Compliance Decision
Task 6.3 closes Domain 6 with two deceptively simple bullets: "formal notification of compliance decision" and "formal notification shared with stakeholders." The exam's angle is that a decision which exists only in the Authorizing Official's inbox has no operational effect — the parties who must act on it cannot act on what they have not received.
1. The Authorization Decision Document
The AO's determination is captured in a formal artifact, commonly the Authorization Decision Document or ATO letter. Four elements are mandatory:
| Element | Content |
|---|---|
| The decision | ATO, ATO with conditions, IATT, ATU, or DATO — stated unambiguously |
| Terms and conditions | Binding constraints: POA&M items with deadlines, restrictions on data types or user populations, required monitoring, prohibited configurations |
| Authorization duration | A termination date, or the basis and conditions for ongoing authorization where the organization operates a continuous authorization model |
| Residual risk statement | An explicit statement of the risk being accepted, so the acceptance is visible rather than implied |
The residual risk statement is what makes the decision meaningful. An ATO letter that simply grants authorization without naming what risk is being accepted does not evidence that the AO understood the decision — which is the entire purpose of the package.
Supporting content typically includes the identity and signature of the AO, the system name and unique identifier, the authorization boundary reference, the package version relied upon, the date, and the conditions under which the authorization may be suspended or revoked.
[!IMPORTANT] Terms and conditions are binding, not advisory. If the decision states that all Moderate POA&M items must close within 90 days, missing that deadline without an approved extension gives the AO grounds to suspend or revoke the authorization. Candidates who treat conditions as aspirational misread the instrument: it is the mechanism by which an AO authorizes a system that is not yet fully compliant while retaining leverage.
2. Who Must Be Notified
Distribution is not a courtesy list. Each recipient has an action to take.
| Recipient | Why They Need It |
|---|---|
| System Owner | Must operate within the terms and satisfy the conditions |
| ISSO / ISSM | Executes continuous monitoring and tracks conditions |
| Common Control Providers | Learn that another system now depends on their controls |
| Systems inheriting from this system | Their own risk posture depends on this authorization remaining valid |
| Interconnection partners | Their agreements are predicated on this system's authorization status |
| CIO / CISO | Enterprise portfolio and FISMA reporting |
| Risk Executive (Function) | Aggregate enterprise risk view |
| SAOP | Where privacy risk was accepted |
| Security Control Assessor | Closes the assessment cycle |
| Inventory / GRC repository owners | Must record the status change |
The two rows candidates overlook are inheriting systems and interconnection partners. Both have made risk decisions premised on this system's status. A partner operating an interconnection with a system whose authorization has lapsed is carrying risk they do not know about, which is why interconnection agreements customarily require notification of authorization changes.
3. What the Decision Triggers
Authorization is a state change with concrete consequences that must actually be executed:
- Inventory update. The system's status, authorization date, expiration, and impact level are recorded in the enterprise repository — eMASS, CSAM, or equivalent. This is what feeds FISMA reporting.
- Continuous monitoring activation. The approved ISCM strategy moves from planned to operational. Monitoring does not begin at the first scheduled scan; it begins when authorization takes effect.
- POA&M tracking begins against the dates in the terms and conditions.
- The authorization clock starts — either toward a termination date or against ongoing-authorization conditions.
- Inheritance relationships become live, so consuming systems may cite this authorization.
- Operational permission is granted. The system may process the data types and support the user populations described in the package — and no others.
That final constraint is examinable. Authorization is bounded by the package it was granted against. Adding a new data type or user population that the package did not describe is a change requiring security impact analysis, not an operational adjustment.
4. Communicating Conditional Decisions and Denials
ATO With Conditions
The most common real-world outcome. Communication must be unambiguous about what the conditions are, when they are due, who owns each one, and what happens if they are missed. A conditional ATO communicated as though it were unconditional produces a system operating past deadlines nobody was tracking — and an authorization that is technically voidable.
Denial of Authorization to Operate
A DATO requires the same rigor as an approval, plus explicit direction on disposition. The communication states the decision, the specific deficiencies that drove it, what would be required to obtain authorization, and — critically — what happens to the system now: whether it must be disconnected immediately, may continue in a restricted mode, or must be decommissioned. A denial that omits disposition guidance leaves operational staff without direction on a system they have been told not to authorize.
For an operating system, a DATO or revocation is disruptive by design, and the communication should reach the mission owner directly rather than through the security chain alone, since mission continuity decisions follow immediately.
Suspension and Revocation
Where an authorization is withdrawn mid-cycle — conditions missed, a significant unassessed change, a serious incident — the notification states the reason, the effective date and time, the required actions, and the path to restoration. These are urgent communications, and the distribution list is the same one that received the original decision, which is a practical reason to maintain that list accurately from the outset.
[!NOTE] Records retention. Authorization decision documents are part of the system's permanent record and are retained per the organization's records schedule — commonly for the life of the system plus a defined period. They are primary evidence in audits, oversight reviews, and incident investigations, and are among the first artifacts an Inspector General requests. The record should also show when notification was sent and to whom, since the ability to demonstrate that stakeholders were informed is exactly what is questioned after something goes wrong.
An Authorizing Official issues an ATO with conditions requiring three Moderate POA&M items to close within 90 days. The system owner treats these as target dates and misses them without requesting an extension. What is the consequence?
Which stakeholders are most commonly omitted from authorization decision distribution, despite having made risk decisions that depend on the system's authorization status?
An Authorizing Official denies authorization for a system already operating in production. Beyond stating the decision and the deficiencies that drove it, what must the communication include?