Which TWO factors should an ISSO consider when determining if a system change requires a re-authorization?
If controls are weakened, it requires re-evaluation.
Why this answer
The magnitude of the change and the impact on the security controls are the two key triggers for re-authorization.