CAP Documentation and Authorization Artifacts 1 — Questions and Answers
Question 1: Which document in the authorization package describes known vulnerabilities and the schedule to fix them?
- System Security Plan
- Security Assessment Report
- Plan of Action and Milestones (Correct answer)
- Authorization Decision Letter
Correct answer: Plan of Action and Milestones
The Plan of Action and Milestones (POA&M) tracks identified weaknesses, responsible parties, resources needed, and target completion dates.
Question 2: What is the minimum set of documents typically included in an authorization package?
- SSP only
- SSP, SAR, and POA&M (Correct answer)
- SAR and POA&M only
- SSP and ATO letter only
Correct answer: SSP, SAR, and POA&M
The standard authorization package contains the System Security Plan, Security Assessment Report, and Plan of Action and Milestones.
Question 3: What information is typically included in the authorization boundary diagram?
- Employee organizational chart
- All hardware, software, and data flows within the system boundary (Correct answer)
- Only external connections
- Vendor contracts and SLAs
Correct answer: All hardware, software, and data flows within the system boundary
The authorization boundary diagram visually represents all system components, interfaces, data flows, and interconnections within scope.
Question 4: A Privacy Impact Assessment (PIA) is required under which federal law before collecting or using personally identifiable information?
- FISMA
- E-Government Act of 2002 (Correct answer)
- Privacy Act of 1974
- HIPAA
Correct answer: E-Government Act of 2002
The E-Government Act of 2002 requires federal agencies to conduct PIAs before developing or procuring IT systems that collect PII.
Question 5: What is the purpose of a System of Records Notice (SORN)?
- To document system vulnerabilities
- To publicly notify citizens about federal systems that collect and use their personal data (Correct answer)
- To list authorized system users
- To grant database access permissions
Correct answer: To publicly notify citizens about federal systems that collect and use their personal data
A SORN is published in the Federal Register to inform the public about systems that maintain personally identifiable information about individuals.
Question 6: Which section of the System Security Plan describes the system's purpose, architecture, and operating environment?
- System Identification (Correct answer)
- Security Control Implementation
- Rules of Behavior
- Interconnections
Correct answer: System Identification
The System Identification section provides the high-level description of the system including its purpose, boundaries, architecture, and environment.
Which document in the authorization package describes known vulnerabilities and the schedule to fix them?