Security Control Assessment & Security Assessment Reports (SAR) Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Security Control Assessment & Security Assessment Reports (SAR) flashcards as text
Which NIST publication provides the methodology for assessing the effectiveness of security controls in federal information systems?
Answer: NIST SP 800-53A
NIST SP 800-53A ('Assessing Security and Privacy Controls in Information Systems and Organizations') provides the procedures for assessing each control in NIST SP 800-53. It defines assessment methods (examine, interview, test) and procedures aligned to each control.
NIST SP 800-53A defines three assessment methods. Which set correctly identifies all three?
Answer: Examine, Interview, Test
NIST SP 800-53A defines three assessment methods: Examine (reviewing documentation and artifacts), Interview (discussing controls with personnel), and Test (exercising the control through technical or operational means). These three methods together provide comprehensive coverage of control effectiveness.
What is the primary output document produced at the conclusion of a security control assessment?
Answer: Security Assessment Report (SAR)
The Security Assessment Report (SAR) documents the assessor's findings, including which controls are effective (satisfied), which are partially effective (other than satisfied), and which are ineffective (not satisfied). The SAR is a key input to the authorization decision.
Why is assessor independence important in the security control assessment process?
Answer: It prevents conflicts of interest where the assessor might overlook deficiencies in controls they helped implement.
Assessor independence (as described in NIST SP 800-37 and SP 800-53A) is critical because individuals who designed or implemented controls have an inherent conflict of interest when assessing those same controls. Independent assessment provides objective, unbiased results for the AO's decision.
After a security assessment identifies control weaknesses that cannot be immediately remediated, what document is used to track the planned remediation actions?
Answer: Plan of Action and Milestones (POA&M)
The Plan of Action and Milestones (POA&M) is the formal document used to track identified weaknesses, the actions planned to correct them, the resources required, and the target completion dates. The POA&M is reviewed by the AO as part of the authorization package.
Which of the following items is NOT typically included in an authorization package submitted to the Authorizing Official?
Answer: Penetration Test Scope Agreement
The standard authorization package per NIST SP 800-37 consists of three core documents: the SSP, the SAR, and the POA&M. A penetration test scope agreement is a pre-engagement document used in contracting, not a formal component of the authorization package.