Authority & chain of command
Who is authorized, in what order, and the cryptographic controls that protect their decisions — the senior approvers for elevated risk, the full roster, per-person signing keys, and the break-glass “encryption of authority.” Cited to NIST SP 800-37 (roles), NIST SP 800-53 AC-5 (separation of duties) and NIST FIPS 198-1 (keyed-hash signatures).
How authority flows NIST SP 800-37
Per risk (horizontal) — each stage hands authority to a different person; no one verifies or authorizes their own work NIST SP 800-53 AC-5:
anyone raises it → Triage
manager assigns the owner → Treat
owner / implementer → Verify
independent assessor (≠ owner) → Authorize & Close
authorizing official → Reopen
named authority
Governance (vertical) — the Three Lines model:
| Line | Who | Authority over risk |
|---|---|---|
| 1st line | Owners / implementers | own & manage the risk day-to-day |
| 2nd line | Risk & compliance (CISO / risk committee) | set policy, oversee, make the accept / authorize decisions |
| 3rd line | Internal audit / independent assessors | independent assurance — verify it is real |
| Above all | Board / executive | own the carried risk; set the risk appetite |
Escalation flows upward: the higher the residual, the more senior the sign-off NIST SP 800-37 and the shorter its validity. The break-glass key below is the logged exception path when normal authority must be bypassed.
⭐ Authorized senior approvers NIST SP 800-37
The important roles, called out on their own. A High or Critical residual risk can't be closed on an ordinary sign-off — it must be accepted by a designated senior authority who also ticks an acknowledgement. Set a person's role to Senior approver or Executive / board on their profile to place them here.
⚠ No senior approvers yet — a High or Critical residual can't be closed until someone here holds the Senior approver or Executive / board role (or you use the break-glass override).
Chain of command NIST SP 800-37
Who is authorized and in what order (most senior first). Each authority is managed on their own profile — click a name to set their role, details and signing key. Add a new authority with New profile.
No one in the chain of command yet — create the first authority with New profile.
Break-glass override key NIST FIPS 198-1
Overriding a quality gate — or reopening a sealed risk — bypasses a control, so it is gated behind a secret held by a named authority (the encryption of authority). Every override is HMAC-signed under that authority's key into the tamper-evident audit trail, so the record names who authorised the exception. The key is stored only as a SHA-256 hash.
🔑 A key is set — held by the authority Class instructor (RESET_KEY). Overrides and reopens require it, and each is HMAC-signed under this authority.
Add someone to the chain of command first — the break-glass key must be held by a named authority.