CAP CAP Security Documentation & Authorization Artifacts 1 — Questions and Answers
Question 1: Which document serves as the primary artifact in the NIST RMF that describes the security controls implemented in an information system?
- Plan of Action and Milestones (POA&M)
- System Security Plan (SSP) (Correct answer)
- Security Assessment Report (SAR)
- Authorization to Operate (ATO)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) is the primary security documentation artifact that describes how an information system implements required security controls.
Question 2: What is the primary purpose of a Plan of Action and Milestones (POA&M) in the RMF process?
- To document system hardware inventory
- To track and remediate identified security weaknesses and deficiencies (Correct answer)
- To authorize a system for operation
- To record user access permissions
Correct answer: To track and remediate identified security weaknesses and deficiencies
A POA&M documents identified security weaknesses, the resources required to fix them, scheduled completion dates, and responsible parties for remediation.
Question 3: Who is responsible for signing and issuing an Authorization to Operate (ATO) for a federal information system?
- System Owner
- Information System Security Officer (ISSO)
- Authorizing Official (AO) (Correct answer)
- Security Control Assessor (SCA)
Correct answer: Authorizing Official (AO)
The Authorizing Official (AO) is the senior federal official with the authority to accept residual risk and issue an ATO for an information system.
Question 4: Which RMF artifact documents the results of security control assessments performed by an independent assessor?
- System Security Plan (SSP)
- Privacy Impact Assessment (PIA)
- Security Assessment Report (SAR) (Correct answer)
- Contingency Plan
Correct answer: Security Assessment Report (SAR)
The Security Assessment Report (SAR) documents the findings and recommendations of the security control assessor after evaluating implemented controls.
Question 5: What type of authorization boundary defines the scope of an information system for RMF documentation purposes?
- Physical perimeter
- Authorization boundary (Correct answer)
- Network perimeter
- Trust boundary
Correct answer: Authorization boundary
The authorization boundary defines all components (hardware, software, data, and users) that are included within the scope of the security authorization package.
Question 6: Which document type defines the specific test procedures used to assess whether security controls are implemented correctly?
- System Security Plan (SSP)
- Security Assessment Plan (SAP) (Correct answer)
- Privacy Impact Assessment (PIA)
- Interconnection Security Agreement (ISA)
Correct answer: Security Assessment Plan (SAP)
The Security Assessment Plan (SAP) defines the scope, schedule, assessment methods, and test procedures the assessor will use to evaluate security controls.
Which document serves as the primary artifact in the NIST RMF that describes the security controls implemented in an information system?