← All CAP Flashcard Decks

Security Authorization Documentation Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Security Authorization Documentation flashcards as text
  1. What is the primary purpose of a System Security Plan (SSP)?

    Answer: To describe security requirements and document controls implemented for an information system

    The SSP is the central document describing system characteristics, the security environment, and how controls are implemented.

  2. Which artifact in the authorization package summarizes the findings from security control testing?

    Answer: Security Assessment Report (SAR)

    The SAR documents the results of the security assessment, including findings, evidence, and recommendations.

  3. What are the three core documents that make up a standard RMF authorization package?

    Answer: SSP, SAR, and POA&M

    The authorization package submitted to the AO consists of the System Security Plan, Security Assessment Report, and Plan of Action and Milestones.

  4. What information must a System Security Plan include about the system boundary?

    Answer: A description of the authorization boundary defining which components are within scope

    The SSP must clearly define the authorization boundary to establish what hardware, software, and services are in scope for the assessment.

  5. Which section of the SSP typically describes how the system processes, stores, or transmits federal information?

    Answer: System Description / Operational Environment

    The system description section explains the system's purpose, data flows, and operational context including what information it handles.

  6. What does the term 'authorization boundary' mean in the context of an SSP?

    Answer: The logical or physical perimeter defining all system components under a single ATO

    The authorization boundary encompasses all system components—hardware, software, firmware, and people—included under one authorization decision.