CAP Security Documentation & Authorization Artifacts Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CAP Security Documentation & Authorization Artifacts flashcards as text
Which document in the RMF authorization package formally describes the boundary of the information system being assessed?
Answer: System Security Plan (SSP)
The SSP defines the authorization boundary, system description, and security controls implemented for the information system.
When an inherited control does not fully satisfy a system's security requirements, what artifact documents the system-specific additions needed?
Answer: Control implementation statement supplement
A control implementation statement supplement documents how the inheriting system fills gaps left by a partially inherited common control.
Which NIST document provides the standardized format and content requirements for Security Assessment Reports?
Answer: NIST SP 800-53A
NIST SP 800-53A provides assessment procedures and guidance on documenting findings in the Security Assessment Report.
An organization discovers a critical vulnerability after the ATO is issued. Which authorization artifact must be IMMEDIATELY updated?
Answer: Plan of Action and Milestones (POA&M)
The POA&M must be updated immediately to document the newly discovered vulnerability, its risk level, and planned remediation timeline.
What is the primary purpose of the Authorization Decision Document signed by the Authorizing Official?
Answer: Formally accept residual risk and grant or deny system operation
The Authorization Decision Document (ADD) is the AO's formal statement accepting residual risk and granting, denying, or conditionally granting ATO.
Which section of the System Security Plan (SSP) would describe how a system handles personally identifiable information (PII)?
Answer: Privacy considerations and Privacy Impact Assessment reference
The SSP references privacy considerations and links to the Privacy Impact Assessment when the system processes PII.
What distinguishes a Memorandum of Understanding (MOU) from an Interconnection Security Agreement (ISA) as authorization artifacts?
Answer: ISAs detail technical/security requirements for connections; MOUs define organizational responsibilities
An ISA documents the technical and security requirements governing a specific interconnection, while an MOU defines the broader organizational roles and responsibilities.