โ† All CAP Flashcard Decks

CAP Security Documentation & Authorization Artifacts Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CAP Security Documentation & Authorization Artifacts flashcards as text
  1. What is the typical validity period for an Authorization to Operate (ATO) issued under FISMA?

    Answer: 3 years

    Under FISMA, an ATO is typically valid for three years, after which the system must undergo reauthorization unless continuous monitoring replaces periodic reauthorization.

  2. A Privacy Impact Assessment (PIA) is required when a federal system meets which criterion?

    Answer: When the system collects, maintains, or disseminates personally identifiable information (PII)

    A PIA is required under the E-Government Act of 2002 whenever a federal system collects, maintains, or disseminates PII to assess privacy risks and mitigation measures.

  3. Which authorization type allows a system to operate with identified weaknesses while remediation is in progress?

    Answer: Interim Authorization to Operate (IATO)

    An Interim Authorization to Operate (IATO) permits temporary operation of a system with known deficiencies, provided a remediation plan is in place and residual risk is acceptable.

  4. What does the 'tailoring' process in RMF documentation involve?

    Answer: Adjusting baseline security controls to match system-specific conditions, risk tolerance, and mission needs

    Tailoring is the process of customizing a security control baseline by adding, removing, or modifying controls to appropriately address the specific risk environment of the system.

  5. Which element must be included in a POA&M entry to satisfy FISMA reporting requirements?

    Answer: Source of the weakness, scheduled completion date, and responsible point of contact

    FISMA-compliant POA&M entries must document the weakness source (e.g., assessment, audit), scheduled remediation date, and the responsible individual or office accountable for closure.

  6. An organization uses a cloud service provider that holds a FedRAMP authorization. How does this affect the system owner's SSP?

    Answer: The system owner can inherit FedRAMP-authorized controls and document them as inherited in their SSP

    System owners can leverage FedRAMP-authorized cloud services by inheriting assessed controls, which reduces their control implementation burden and is documented as inherited controls in the SSP.