Who determines whether a security reaccreditation is required after reviewing the plan of actions and milestones?
a. The senior information system security officer
b. The authorizing official
c. The senior information security officer and the authorizing official
d. The information system owner