CAP Documentation and Authorization Artifacts 2 — Questions and Answers
Question 1: Rules of Behavior (RoB) documents are required to inform which stakeholders of their security responsibilities?
- System owners only
- Authorizing Officials only
- All users who access the information system (Correct answer)
- Network administrators only
Correct answer: All users who access the information system
Rules of Behavior must be acknowledged by all users (employees, contractors, guests) who access the system before they are granted access.
Question 2: What is a Memorandum of Understanding (MOU) used for in the context of information system authorization?
- Replacing the SSP for low-impact systems
- Documenting agreed-upon responsibilities between two or more organizations sharing a system or service (Correct answer)
- Granting temporary access to contractors
- Replacing the POA&M
Correct answer: Documenting agreed-upon responsibilities between two or more organizations sharing a system or service
An MOU documents the responsibilities and agreements between organizations regarding shared systems, services, or data.
Question 3: How does a Memorandum of Agreement (MOA) differ from a Memorandum of Understanding (MOU)?
- An MOA is legally binding with specific commitments; an MOU is less formal and states intent (Correct answer)
- An MOA applies only to classified systems; an MOU applies to unclassified systems
- An MOU requires congressional approval; an MOA does not
- There is no practical difference
Correct answer: An MOA is legally binding with specific commitments; an MOU is less formal and states intent
An MOA typically outlines binding commitments and obligations, while an MOU generally expresses a less formal mutual understanding.
Question 4: The authorization decision letter issued by the AO must include which key element?
- A full list of all security controls
- The authorization termination date or conditions (Correct answer)
- The names of all system users
- The system's IP addresses
Correct answer: The authorization termination date or conditions
The authorization decision letter must specify the authorization period or the conditions under which the authorization will be terminated.
Question 5: What is the role of the Information System Security Officer (ISSO) in maintaining authorization documentation?
- Granting the ATO
- Conducting independent security assessments
- Maintaining and updating system security documentation and coordinating with the AO (Correct answer)
- Approving user access requests
Correct answer: Maintaining and updating system security documentation and coordinating with the AO
The ISSO is responsible for day-to-day security operations, ensuring documentation stays current, and reporting security status to the AO.
Question 6: What does an agency's contingency plan document describe?
- How to handle data breaches only
- Procedures to recover information system operations after a disruption or disaster (Correct answer)
- Network configuration backups
- Vendor escalation procedures
Correct answer: Procedures to recover information system operations after a disruption or disaster
A contingency plan defines the procedures for maintaining or restoring operations of an information system following a disruption.
Rules of Behavior (RoB) documents are required to inform which stakeholders of their security responsibilities?