โ† All CAP Flashcard Decks

CAP Security Documentation & Authorization Artifacts Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CAP Security Documentation & Authorization Artifacts flashcards as text
  1. Which document in the RMF authorization package formally describes the boundary of the information system being assessed?

    Answer: System Security Plan (SSP)

    The SSP defines the authorization boundary, system description, and security controls implemented for the information system.

  2. When an inherited control does not fully satisfy a system's security requirements, what artifact documents the system-specific additions needed?

    Answer: Control implementation statement supplement

    A control implementation statement supplement documents how the inheriting system fills gaps left by a partially inherited common control.

  3. Which NIST document provides the standardized format and content requirements for Security Assessment Reports?

    Answer: NIST SP 800-53A

    NIST SP 800-53A provides assessment procedures and guidance on documenting findings in the Security Assessment Report.

  4. An organization discovers a critical vulnerability after the ATO is issued. Which authorization artifact must be IMMEDIATELY updated?

    Answer: Plan of Action and Milestones (POA&M)

    The POA&M must be updated immediately to document the newly discovered vulnerability, its risk level, and planned remediation timeline.

  5. What is the primary purpose of the Authorization Decision Document signed by the Authorizing Official?

    Answer: Formally accept residual risk and grant or deny system operation

    The Authorization Decision Document (ADD) is the AO's formal statement accepting residual risk and granting, denying, or conditionally granting ATO.

  6. Which section of the System Security Plan (SSP) would describe how a system handles personally identifiable information (PII)?

    Answer: Privacy considerations and Privacy Impact Assessment reference

    The SSP references privacy considerations and links to the Privacy Impact Assessment when the system processes PII.

  7. What distinguishes a Memorandum of Understanding (MOU) from an Interconnection Security Agreement (ISA) as authorization artifacts?

    Answer: ISAs detail technical/security requirements for connections; MOUs define organizational responsibilities

    An ISA documents the technical and security requirements governing a specific interconnection, while an MOU defines the broader organizational roles and responsibilities.