CAP Security Documentation & Authorization Artifacts Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CAP Security Documentation & Authorization Artifacts flashcards as text
What is the typical validity period for an Authorization to Operate (ATO) issued under FISMA?
Answer: 3 years
Under FISMA, an ATO is typically valid for three years, after which the system must undergo reauthorization unless continuous monitoring replaces periodic reauthorization.
A Privacy Impact Assessment (PIA) is required when a federal system meets which criterion?
Answer: When the system collects, maintains, or disseminates personally identifiable information (PII)
A PIA is required under the E-Government Act of 2002 whenever a federal system collects, maintains, or disseminates PII to assess privacy risks and mitigation measures.
Which authorization type allows a system to operate with identified weaknesses while remediation is in progress?
Answer: Interim Authorization to Operate (IATO)
An Interim Authorization to Operate (IATO) permits temporary operation of a system with known deficiencies, provided a remediation plan is in place and residual risk is acceptable.
What does the 'tailoring' process in RMF documentation involve?
Answer: Adjusting baseline security controls to match system-specific conditions, risk tolerance, and mission needs
Tailoring is the process of customizing a security control baseline by adding, removing, or modifying controls to appropriately address the specific risk environment of the system.
Which element must be included in a POA&M entry to satisfy FISMA reporting requirements?
Answer: Source of the weakness, scheduled completion date, and responsible point of contact
FISMA-compliant POA&M entries must document the weakness source (e.g., assessment, audit), scheduled remediation date, and the responsible individual or office accountable for closure.
An organization uses a cloud service provider that holds a FedRAMP authorization. How does this affect the system owner's SSP?
Answer: The system owner can inherit FedRAMP-authorized controls and document them as inherited in their SSP
System owners can leverage FedRAMP-authorized cloud services by inheriting assessed controls, which reduces their control implementation burden and is documented as inherited controls in the SSP.