CAP CAP Security Documentation & Authorization Artifacts 2 — Questions and Answers
Question 1: An Interconnection Security Agreement (ISA) is required when two federal information systems need to share data. What does the ISA primarily document?
- Encryption algorithms used for data at rest
- Security requirements and responsibilities for the connection between systems (Correct answer)
- User account provisioning procedures
- Audit log retention schedules
Correct answer: Security requirements and responsibilities for the connection between systems
An ISA documents the technical and security requirements, roles, and responsibilities governing a specific connection between two interconnected information systems.
Question 2: NIST SP 800-18 provides guidance on which RMF artifact?
- Contingency Planning
- System Security Plan development (Correct answer)
- Security Assessment Reports
- Risk Assessments
Correct answer: System Security Plan development
NIST SP 800-18 provides the Guide for Developing Security Plans for Federal Information Systems, covering SSP structure and content requirements.
Question 3: Which section of a System Security Plan (SSP) describes how a system processes, stores, and transmits information?
- System Identification
- System Environment
- Information System Description (Correct answer)
- Security Controls
Correct answer: Information System Description
The Information System Description section of an SSP provides an overview of the system's purpose, architecture, and how it handles information throughout its lifecycle.
Question 4: What is the significance of 'continuous monitoring' documentation in the context of maintaining an ATO?
- It replaces the need for an SSP after initial authorization
- It provides ongoing evidence that security controls remain effective and risks stay within accepted levels (Correct answer)
- It documents physical security inspections only
- It satisfies FISMA annual training requirements
Correct answer: It provides ongoing evidence that security controls remain effective and risks stay within accepted levels
Continuous monitoring documentation demonstrates that security controls remain effective over time, supporting ongoing authorization and keeping the ATO valid.
Question 5: A 'common control' documented in an SSP refers to which of the following?
- A control applied only to classified systems
- A security control inherited by multiple systems from a shared provider (Correct answer)
- A baseline control applicable to all FISMA systems
- A compensating control approved by the AO
Correct answer: A security control inherited by multiple systems from a shared provider
Common controls are security controls implemented at an organizational level and inherited by multiple information systems, reducing redundant documentation across SSPs.
Question 6: Which NIST publication provides the catalog of security and privacy controls used to populate an SSP for federal systems?
- NIST SP 800-37
- NIST SP 800-53 (Correct answer)
- NIST SP 800-30
- NIST SP 800-61
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the comprehensive catalog of security and privacy controls that federal agencies use to protect information systems and populate SSP control documentation.
An Interconnection Security Agreement (ISA) is required when two federal information systems need to share data.
What does the ISA primarily document?