← All CAP Flashcard Decks

Risk Management Framework Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Risk Management Framework flashcards as text
  1. Which FIPS standard defines the three security objectives: confidentiality, integrity, and availability?

    Answer: FIPS 199

    FIPS 199 establishes the standards for categorizing federal information and information systems using C, I, and A.

  2. What is the purpose of the 'Prepare' step added to RMF in NIST SP 800-37 Revision 2?

    Answer: To establish organizational risk management roles and strategy before system-level activities

    The Prepare step establishes the organizational context and risk management strategy prior to executing system-level RMF tasks.

  3. Who is responsible for accepting residual risk and granting an Authorization to Operate (ATO)?

    Answer: Authorizing Official (AO)

    The Authorizing Official is the senior executive who formally accepts residual risk and grants the ATO.

  4. Which RMF step ensures that security controls are correctly installed and operating as intended?

    Answer: Implement

    The Implement step involves deploying security controls and documenting how they are configured and functioning.

  5. What is a 'common control' in the context of the RMF?

    Answer: A security control inherited by multiple systems from a shared provider

    Common controls are security controls whose implementation is managed at the organizational level and inherited by multiple information systems.

  6. Which document within the RMF authorization package identifies weaknesses and plans to remediate them?

    Answer: Plan of Action and Milestones (POA&M)

    The POA&M tracks identified security weaknesses and documents the corrective actions and timelines for remediation.