Documentation and Authorization Artifacts Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Documentation and Authorization Artifacts flashcards as text
Which document records all security-relevant events and changes affecting an information system over time?
Answer: Configuration Management Log
The configuration management log tracks changes to system components, supporting the ongoing integrity of the system's documented baseline.
A data flow diagram (DFD) in an SSP is used to illustrate what?
Answer: How data moves through the system, including inputs, outputs, and storage
A DFD maps how data enters, travels through, is processed, and exits the information system, supporting privacy and security analysis.
In federal systems, who is primarily responsible for ensuring the SSP is kept current and accurate?
Answer: System Owner
The System Owner has primary responsibility for developing, maintaining, and updating the System Security Plan.
What is typically triggered when a significant change occurs to an authorized information system?
Answer: A security impact analysis and possible re-authorization are initiated
Significant changes require a security impact analysis, and if the risk posture changes materially, re-authorization may be required.
What is the purpose of an authorization boundary in the context of system documentation?
Answer: To define the scope of components, data, and services subject to assessment and authorization
The authorization boundary defines exactly what is included in the assessment and authorization, preventing scope creep during reviews.
Which CAP-related document captures the results of security testing and evaluation activities?
Answer: Security Assessment Report
The Security Assessment Report (SAR) documents the findings, deficiencies, and recommendations from testing and evaluating security controls.