Security Authorization Documentation Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Security Authorization Documentation flashcards as text
What is a 'significant change' that would require reauthorization of a federal information system?
Answer: A major upgrade to system architecture, operating environment, or security posture that increases risk
Significant changes such as new external interconnections, major software upgrades, or changes to the threat environment may trigger reauthorization.
What is the role of the Information System Security Officer (ISSO) in documentation management?
Answer: To develop, maintain, and update security documentation including the SSP and POA&M
The ISSO is responsible for day-to-day security documentation management, including keeping the SSP current and tracking POA&M items.
Which artifact documents interconnections between an information system and external systems?
Answer: Interconnection Security Agreement (ISA) / Memorandum of Understanding (MOU)
ISAs (often paired with MOUs) formally document the terms, security requirements, and authorizations for system interconnections.
What is the maximum ATO period allowed for most federal information systems under NIST guidance?
Answer: Three years
NIST SP 800-37 recommends a maximum three-year ATO period before reauthorization is required.
What must the POA&M include for each identified security weakness?
Answer: Description of the weakness, responsible party, scheduled completion date, and resources needed
A complete POA&M entry includes what the weakness is, who owns remediation, when it will be fixed, and what resources are required.
What is the purpose of a System of Records Notice (SORN) in the federal authorization context?
Answer: To notify the public about a federal system that collects and maintains PII under the Privacy Act
A SORN is published in the Federal Register to inform the public about systems that collect and use personally identifiable information under the Privacy Act.