Security Authorization Documentation Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Security Authorization Documentation flashcards as text
What is the difference between an Authorization to Operate (ATO) and an Interim Authorization to Operate (IATO)?
Answer: An ATO is a full authorization; an IATO is a time-limited authorization granted while residual risks are being mitigated
An IATO allows a system to operate temporarily with known risks under conditions that must be remediated within a specified timeframe.
What does an Authorization Denial (DATO) indicate?
Answer: The AO has determined the risk is unacceptable and the system must not operate
A DATO means the Authorizing Official found the risk too high to accept and prohibits the system from operating.
Which control family in NIST SP 800-53 specifically addresses planning and the System Security Plan?
Answer: PL (Planning)
The PL control family includes PL-2, which specifically requires the development and maintenance of the System Security Plan.
How frequently must federal agencies review and update their System Security Plans per NIST guidance?
Answer: At least annually or whenever significant changes occur
NIST recommends reviewing and updating the SSP at least annually and whenever significant changes to the system occur.
What is the purpose of a Privacy Impact Assessment (PIA) in the authorization process?
Answer: To identify and evaluate privacy risks associated with the collection or use of personally identifiable information
A PIA examines how PII is collected, used, shared, and protected to ensure compliance with privacy laws and mitigate privacy risks.
Which NIST publication provides guidance on preparing the authorization package and submitting it to the AO?
Answer: NIST SP 800-37
NIST SP 800-37 describes the RMF process including the preparation and submission of the authorization package to the Authorizing Official.