Security Controls and Authorization Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Security Controls and Authorization flashcards as text
What is the primary purpose of a security impact analysis?
Answer: To evaluate the effect of proposed changes on a system's security posture
A security impact analysis assesses how a proposed change could affect the confidentiality, integrity, or availability of an information system.
Which three security objectives are used in FIPS 199 to categorize information and systems?
Answer: Confidentiality, Integrity, Availability
FIPS 199 uses potential impacts to confidentiality, integrity, and availability (the CIA triad) to assign security categories.
In the authorization boundary context, what does it mean when a system is described as 'multi-tenant'?
Answer: Multiple organizations share the same infrastructure with logically separated environments
A multi-tenant system allows multiple customers or organizations to share the same underlying infrastructure while maintaining logical separation.
What is the key difference between a Denial of Authorization to Operate (DATO) and an expired ATO?
Answer: A DATO is an active revocation due to unacceptable risk; an expired ATO simply lapsed in time
A DATO is an affirmative decision by the AO to revoke authorization due to unacceptable risk, while an expired ATO simply was not renewed.
Which privacy-related requirement was integrated into NIST SP 800-53 Revision 5?
Answer: Privacy controls were integrated alongside security controls in the same catalog
NIST SP 800-53 Rev. 5 fully integrated privacy controls into the same catalog as security controls, reflecting a unified approach.
What role does the Security Control Assessor (SCA) play in the authorization process?
Answer: Independently evaluates the effectiveness of security controls
The SCA independently assesses whether security controls are correctly implemented and effective, producing the Security Assessment Report.