โ† All CAP Flashcard Decks

Security Control Implementation Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Control Implementation flashcards as text
  1. What does NIST SP 800-53A provide in direct support of the security control implementation and assessment process?

    Answer: Assessment procedures for determining whether implemented controls are effective

    NIST SP 800-53A provides the assessment procedures used to evaluate whether security controls have been correctly implemented and are operating effectively.

  2. What is the significance of documenting implementation status and evidence in the System Security Plan?

    Answer: It provides evidence that assessors and the AO use to evaluate the system's security posture

    Documented implementation evidence gives the security control assessor and Authorizing Official the basis they need to evaluate whether controls are effective and make sound authorization decisions.

  3. When a security control is determined to be 'not applicable' to an information system, what must the system owner do?

    Answer: Document the rationale for non-applicability in the SSP

    Non-applicability determinations must be documented with a clear rationale in the SSP so assessors and the AO can evaluate whether the decision is justified.

  4. What role does the Information System Security Engineer (ISSE) play in security control implementation?

    Answer: Providing technical expertise to ensure controls are properly engineered into the system

    The ISSE applies security engineering expertise to ensure that security controls and requirements are correctly designed and integrated into the system architecture and implementation.

  5. Which of the following is an example of a technical security control implementation?

    Answer: Configuring automated audit log generation and retention on a server

    Technical controls are implemented through hardware, software, or firmware; configuring automated audit logging is a direct technical implementation within the system itself.

  6. How should organizations determine which security controls to allocate as common controls versus system-specific controls?

    Answer: Allocation should be based on organizational efficiency and cost-effectiveness while ensuring adequate protection

    Control allocation decisions should optimize cost-effectiveness and organizational efficiency, leveraging common controls where it makes operational and security sense.

  7. Which NIST RMF task requires organizations to update the System Security Plan to reflect the actual implementation of security controls?

    Answer: Implement security controls (Step 4)

    During Step 4 (Implement), organizations implement the selected controls and update the SSP to reflect how controls were actually implemented, including any deviations from the planned approach.

Security Control Implementation Flashcards โ€” CAP Study Cards with Answers