CAP Continuous Monitoring Strategy 2 — Questions and Answers
Question 1: What is an 'ongoing authorization' in the context of continuous monitoring?
- A risk management approach where the AO makes ongoing authorization decisions based on real-time monitoring data rather than periodic reassessments (Correct answer)
- An ATO that never expires and requires no review
- An automated system that grants ATOs without human review
- A contract with an MSSP for 24/7 monitoring
Correct answer: A risk management approach where the AO makes ongoing authorization decisions based on real-time monitoring data rather than periodic reassessments
Ongoing authorization shifts from periodic reauthorization to a continuous risk-informed process where the AO monitors security posture in real time.
Question 2: What is the role of automated scanning tools in a continuous monitoring program?
- To efficiently collect security state data such as patch levels, configuration compliance, and vulnerabilities at scale (Correct answer)
- To replace the need for human security analysts
- To generate ATOs automatically based on scan results
- To conduct penetration testing on a daily basis
Correct answer: To efficiently collect security state data such as patch levels, configuration compliance, and vulnerabilities at scale
Automated tools enable continuous data collection across large environments, making it feasible to assess many controls frequently without manual effort.
Question 3: What federal initiative provides automated continuous monitoring capabilities and dashboards to federal civilian agencies?
- Continuous Diagnostics and Mitigation (CDM) (Correct answer)
- FedRAMP
- Einstein Program
- HSPD-12
Correct answer: Continuous Diagnostics and Mitigation (CDM)
The CDM program, managed by CISA, provides tools and dashboards to automate continuous monitoring across federal civilian agencies.
Question 4: What should happen when continuous monitoring detects a significant security change to a system?
- The ISSO must notify the AO and update the SSP and risk assessment to reflect the new security posture (Correct answer)
- The system must be immediately shut down
- The POA&M is automatically closed
- The ATO period resets to three years automatically
Correct answer: The ISSO must notify the AO and update the SSP and risk assessment to reflect the new security posture
Significant changes detected during monitoring must be reported to the AO, and associated documentation must be updated to reflect the current risk posture.
Question 5: Which metric is commonly used to measure the effectiveness of a vulnerability management continuous monitoring process?
- Mean Time to Remediate (MTTR) critical vulnerabilities (Correct answer)
- Number of users with admin privileges
- Percentage of systems with an active ATO
- Count of security incidents per quarter
Correct answer: Mean Time to Remediate (MTTR) critical vulnerabilities
MTTR measures how quickly identified vulnerabilities are patched, directly reflecting the effectiveness of the vulnerability management process.
Question 6: What is the purpose of a Plan of Action and Milestones (POA&M) update in the continuous monitoring process?
- To document newly identified weaknesses and track remediation progress over time (Correct answer)
- To replace the SAR after the initial assessment
- To request additional budget for security tools
- To terminate the ATO when a vulnerability is found
Correct answer: To document newly identified weaknesses and track remediation progress over time
Regular POA&M updates during continuous monitoring ensure that newly found weaknesses are documented and remediation activities are tracked and reported.
What is an 'ongoing authorization' in the context of continuous monitoring?