Documentation and Authorization Artifacts Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Documentation and Authorization Artifacts flashcards as text
Rules of Behavior (RoB) documents are required to inform which stakeholders of their security responsibilities?
Answer: All users who access the information system
Rules of Behavior must be acknowledged by all users (employees, contractors, guests) who access the system before they are granted access.
What is a Memorandum of Understanding (MOU) used for in the context of information system authorization?
Answer: Documenting agreed-upon responsibilities between two or more organizations sharing a system or service
An MOU documents the responsibilities and agreements between organizations regarding shared systems, services, or data.
How does a Memorandum of Agreement (MOA) differ from a Memorandum of Understanding (MOU)?
Answer: An MOA is legally binding with specific commitments; an MOU is less formal and states intent
An MOA typically outlines binding commitments and obligations, while an MOU generally expresses a less formal mutual understanding.
The authorization decision letter issued by the AO must include which key element?
Answer: The authorization termination date or conditions
The authorization decision letter must specify the authorization period or the conditions under which the authorization will be terminated.
What is the role of the Information System Security Officer (ISSO) in maintaining authorization documentation?
Answer: Maintaining and updating system security documentation and coordinating with the AO
The ISSO is responsible for day-to-day security operations, ensuring documentation stays current, and reporting security status to the AO.
What does an agency's contingency plan document describe?
Answer: Procedures to recover information system operations after a disruption or disaster
A contingency plan defines the procedures for maintaining or restoring operations of an information system following a disruption.