โ† All CAP Flashcard Decks

CAP Security Documentation & Authorization Artifacts Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CAP Security Documentation & Authorization Artifacts flashcards as text
  1. An Interconnection Security Agreement (ISA) is required when two federal information systems need to share data. What does the ISA primarily document?

    Answer: Security requirements and responsibilities for the connection between systems

    An ISA documents the technical and security requirements, roles, and responsibilities governing a specific connection between two interconnected information systems.

  2. NIST SP 800-18 provides guidance on which RMF artifact?

    Answer: System Security Plan development

    NIST SP 800-18 provides the Guide for Developing Security Plans for Federal Information Systems, covering SSP structure and content requirements.

  3. Which section of a System Security Plan (SSP) describes how a system processes, stores, and transmits information?

    Answer: Information System Description

    The Information System Description section of an SSP provides an overview of the system's purpose, architecture, and how it handles information throughout its lifecycle.

  4. What is the significance of 'continuous monitoring' documentation in the context of maintaining an ATO?

    Answer: It provides ongoing evidence that security controls remain effective and risks stay within accepted levels

    Continuous monitoring documentation demonstrates that security controls remain effective over time, supporting ongoing authorization and keeping the ATO valid.

  5. A 'common control' documented in an SSP refers to which of the following?

    Answer: A security control inherited by multiple systems from a shared provider

    Common controls are security controls implemented at an organizational level and inherited by multiple information systems, reducing redundant documentation across SSPs.

  6. Which NIST publication provides the catalog of security and privacy controls used to populate an SSP for federal systems?

    Answer: NIST SP 800-53

    NIST SP 800-53 provides the comprehensive catalog of security and privacy controls that federal agencies use to protect information systems and populate SSP control documentation.