Documentation and Authorization Artifacts Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Documentation and Authorization Artifacts flashcards as text
Which document in the authorization package describes known vulnerabilities and the schedule to fix them?
Answer: Plan of Action and Milestones
The Plan of Action and Milestones (POA&M) tracks identified weaknesses, responsible parties, resources needed, and target completion dates.
What is the minimum set of documents typically included in an authorization package?
Answer: SSP, SAR, and POA&M
The standard authorization package contains the System Security Plan, Security Assessment Report, and Plan of Action and Milestones.
What information is typically included in the authorization boundary diagram?
Answer: All hardware, software, and data flows within the system boundary
The authorization boundary diagram visually represents all system components, interfaces, data flows, and interconnections within scope.
A Privacy Impact Assessment (PIA) is required under which federal law before collecting or using personally identifiable information?
Answer: E-Government Act of 2002
The E-Government Act of 2002 requires federal agencies to conduct PIAs before developing or procuring IT systems that collect PII.
What is the purpose of a System of Records Notice (SORN)?
Answer: To publicly notify citizens about federal systems that collect and use their personal data
A SORN is published in the Federal Register to inform the public about systems that maintain personally identifiable information about individuals.
Which section of the System Security Plan describes the system's purpose, architecture, and operating environment?
Answer: System Identification
The System Identification section provides the high-level description of the system including its purpose, boundaries, architecture, and environment.