Risk Management & Security Evaluation Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Security Evaluation flashcards as text
Which NIST publication provides the primary framework for federal information security risk management using the Risk Management Framework (RMF)?
Answer: NIST SP 800-37
NIST SP 800-37 defines the RMF and its six steps (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) for federal systems.
During a security assessment, an assessor discovers that a control is partially implemented. How should this finding be recorded in the Security Assessment Report (SAR)?
Answer: As 'Other Than Satisfied' with documented weaknesses
A partially implemented control is recorded as 'Other Than Satisfied' in the SAR, with the specific weaknesses and deficiencies documented.
What is the primary purpose of a Plan of Action and Milestones (POA&M)?
Answer: To document and track remediation of security weaknesses identified during assessment
A POA&M documents identified weaknesses, assigns responsibility, and establishes scheduled milestones for corrective action.
Under FISMA, who is ultimately responsible for accepting the residual risk of operating a federal information system?
Answer: Authorizing Official (AO)
The Authorizing Official (AO) bears ultimate responsibility for accepting residual risk by signing the Authorization to Operate (ATO).
Which risk response strategy involves transferring potential loss to a third party, such as through cyber insurance?
Answer: Risk Transference
Risk transference shifts financial or operational consequences of a risk to another party, such as an insurer or cloud service provider.
What document formally describes the security controls implemented for a federal information system and serves as the primary security planning artifact?
Answer: System Security Plan (SSP)
The System Security Plan (SSP) is the primary document describing security requirements and the controls in place or planned for a system.
A system is categorized as HIGH for confidentiality, MODERATE for integrity, and LOW for availability. What is the overall FIPS 199 categorization?
Answer: HIGH
FIPS 199 uses the 'high water mark' principle — the overall system categorization equals the highest impact level across all three security objectives.