โ† All CAP Flashcard Decks

CAP Security Documentation & Authorization Artifacts Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CAP Security Documentation & Authorization Artifacts flashcards as text
  1. In a continuous monitoring program, how frequently must POA&M entries be reviewed at minimum according to NIST guidance?

    Answer: Monthly

    NIST SP 800-137 recommends monthly POA&M reviews as part of ongoing authorization and continuous monitoring activities.

  2. Which artifact specifically documents the agreement between a cloud service provider and a federal agency regarding shared security responsibilities?

    Answer: Customer Responsibility Matrix (CRM)

    The Customer Responsibility Matrix (also called Shared Responsibility Matrix) explicitly delineates which security controls are managed by the CSP versus the agency.

  3. A system owner wants to reuse security assessment results from a similar system assessed 14 months ago. What is the primary concern with this approach?

    Answer: The previous SAR may be outside the acceptable reuse window, typically 12 months

    NIST guidance generally limits reuse of assessment evidence to within 12 months, as older results may not reflect the current security posture.

  4. Which document would an ISSO reference to determine the specific assessment methods (examine, interview, test) required for each security control?

    Answer: NIST SP 800-53A Revision 5

    NIST SP 800-53A provides the assessment procedures, including whether each control requires examination of artifacts, interviews with personnel, or technical testing.

  5. What is the purpose of including a 'control origination' field in the SSP control implementation statements?

    Answer: Indicate whether a control is system-specific, hybrid, inherited, or common

    The control origination field clarifies accountability by showing whether a control is implemented locally, shared with a common control provider, or a hybrid arrangement.

  6. When preparing an authorization package for a system with a HIGH confidentiality impact level, which additional artifact is typically required compared to a MODERATE system?

    Answer: More rigorous penetration test results documented in the SAR

    HIGH-impact systems typically require more rigorous independent security testing, with detailed penetration test findings documented within or appended to the Security Assessment Report.

  7. Under RMF, which artifact serves as the 'living document' that must be updated throughout the system lifecycle, not just at authorization time?

    Answer: System Security Plan (SSP)

    The SSP is a living document that must be kept current throughout the system's lifecycle, updated whenever significant changes occur or controls are modified.