โ† All CAP Flashcard Decks

Risk Management & Security Evaluation Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Management & Security Evaluation flashcards as text
  1. Which NIST SP 800-137 concept refers to the ongoing process of monitoring security controls to maintain awareness of the system's security posture over time?

    Answer: Information Security Continuous Monitoring (ISCM)

    ISCM, defined in NIST SP 800-137, is the ongoing process of maintaining situational awareness of information security to support risk management decisions.

  2. When a significant change is made to an authorized system, what process must the ISSO initiate before implementing the change?

    Answer: Security Impact Analysis (SIA)

    A Security Impact Analysis (SIA) evaluates the potential security effects of a proposed change before implementation to determine if reauthorization is required.

  3. What term describes the minimum set of security controls required for a given impact level (Low, Moderate, High) under NIST SP 800-53?

    Answer: Security Control Baseline

    A security control baseline is the predefined starting set of controls recommended by NIST for Low, Moderate, or High impact systems before tailoring.

  4. Which of the following BEST describes a 'compensating control' in the RMF context?

    Answer: An alternative control that provides equivalent protection when the required control cannot be implemented

    A compensating control provides equivalent or comparable protection to the required control when the latter is technically or operationally infeasible to implement.

  5. An agency's AO reviews an authorization package and determines the residual risk is too high to accept. What authorization decision should the AO issue?

    Answer: Denial of Authorization to Operate (DATO)

    A DATO is issued when the AO determines that residual risk exceeds acceptable thresholds and the system cannot be authorized to operate.

  6. Under the RMF, which role is responsible for developing and maintaining the System Security Plan (SSP)?

    Answer: Information System Owner (ISO)

    The Information System Owner (ISO) is responsible for developing, maintaining, and updating the SSP as the primary steward of the system's security documentation.

  7. What is the primary risk management benefit of implementing a 'zero trust architecture' in a federal environment?

    Answer: It eliminates implicit trust based on network location, requiring continuous verification of all users and devices

    Zero trust eliminates the assumption that anything inside the network perimeter is trusted, requiring explicit verification of identity and context for every access request.