Security assessment and authorization
An assessment of a system's security posture leading to a formal decision to operate it.
Plain English
The process of assessing a system's security risks and having someone senior formally accept them before it goes live.
If you’re new here
It takes longer than teams plan for and cannot start the week before launch. Someone has to put their name to the residual risk, and they will want to read first.
What they probably mean
“Nothing goes live until a named person signs for the risk.”
Interpretation offered as humour, not authoritative guidance.
Bureaucracy level
How much government-speak this phrase carries. Playful indicator, not a judgement of anyone using it.
Related terms
Was this explanation helpful?