CAP Security Documentation & Authorization Artifacts Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CAP Security Documentation & Authorization Artifacts flashcards as text
Which document serves as the primary artifact in the NIST RMF that describes the security controls implemented in an information system?
Answer: System Security Plan (SSP)
The System Security Plan (SSP) is the primary security documentation artifact that describes how an information system implements required security controls.
What is the primary purpose of a Plan of Action and Milestones (POA&M) in the RMF process?
Answer: To track and remediate identified security weaknesses and deficiencies
A POA&M documents identified security weaknesses, the resources required to fix them, scheduled completion dates, and responsible parties for remediation.
Who is responsible for signing and issuing an Authorization to Operate (ATO) for a federal information system?
Answer: Authorizing Official (AO)
The Authorizing Official (AO) is the senior federal official with the authority to accept residual risk and issue an ATO for an information system.
Which RMF artifact documents the results of security control assessments performed by an independent assessor?
Answer: Security Assessment Report (SAR)
The Security Assessment Report (SAR) documents the findings and recommendations of the security control assessor after evaluating implemented controls.
What type of authorization boundary defines the scope of an information system for RMF documentation purposes?
Answer: Authorization boundary
The authorization boundary defines all components (hardware, software, data, and users) that are included within the scope of the security authorization package.
Which document type defines the specific test procedures used to assess whether security controls are implemented correctly?
Answer: Security Assessment Plan (SAP)
The Security Assessment Plan (SAP) defines the scope, schedule, assessment methods, and test procedures the assessor will use to evaluate security controls.