โ† All CAP Flashcard Decks

Continuous Monitoring Strategy Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Continuous Monitoring Strategy flashcards as text
  1. What is the difference between configuration management and continuous monitoring?

    Answer: Configuration management establishes and maintains secure baselines; continuous monitoring verifies those baselines are maintained over time

    Configuration management defines the desired security state, while continuous monitoring checks that the system continues to operate in that desired state.

  2. How does FedRAMP use continuous monitoring for cloud service providers?

    Answer: CSPs must provide monthly vulnerability scans, annual penetration tests, and ongoing POA&M updates to maintain their FedRAMP authorization

    FedRAMP's continuous monitoring requirements include monthly vulnerability scanning, annual penetration testing, and regular POA&M tracking to maintain authorization.

  3. What is a 'security status report' in the context of continuous monitoring?

    Answer: A periodic report provided to the AO summarizing the current security posture, monitoring results, and risk levels

    Security status reports keep the AO informed of the system's ongoing security posture between formal reauthorization events.

  4. What does 'risk tolerance' mean in the context of defining a continuous monitoring strategy?

    Answer: The degree of risk the organization is willing to accept while still achieving its mission objectives

    Risk tolerance defines how much residual risk leadership is willing to accept, which informs what to monitor, how frequently, and what triggers escalation.

  5. Which NIST SP 800-137 activity involves reviewing and revising the continuous monitoring program based on lessons learned?

    Answer: Review/Update

    The Review/Update step ensures the continuous monitoring program evolves based on changing threats, technology, and lessons learned from findings.

  6. What is an 'inherited control' in the context of continuous monitoring for a leveraged system?

    Answer: A security control implemented by a common control provider whose monitoring responsibilities are inherited rather than duplicated by the leveraging system

    When a system inherits a common control, the monitoring responsibility for that control lies with the common control provider, not the system owner.