CAP Risk Management Framework 2 — Questions and Answers
Question 1: Which FIPS standard defines the three security objectives: confidentiality, integrity, and availability?
- FIPS 199 (Correct answer)
- FIPS 200
- FIPS 140-2
- FIPS 201
Correct answer: FIPS 199
FIPS 199 establishes the standards for categorizing federal information and information systems using C, I, and A.
Question 2: What is the purpose of the 'Prepare' step added to RMF in NIST SP 800-37 Revision 2?
- To establish organizational risk management roles and strategy before system-level activities (Correct answer)
- To select baseline security controls
- To implement controls across the enterprise
- To authorize the information system
Correct answer: To establish organizational risk management roles and strategy before system-level activities
The Prepare step establishes the organizational context and risk management strategy prior to executing system-level RMF tasks.
Question 3: Who is responsible for accepting residual risk and granting an Authorization to Operate (ATO)?
- Authorizing Official (AO) (Correct answer)
- System Owner
- ISSO
- Security Control Assessor
Correct answer: Authorizing Official (AO)
The Authorizing Official is the senior executive who formally accepts residual risk and grants the ATO.
Question 4: Which RMF step ensures that security controls are correctly installed and operating as intended?
- Implement (Correct answer)
- Select
- Authorize
- Monitor
Correct answer: Implement
The Implement step involves deploying security controls and documenting how they are configured and functioning.
Question 5: What is a 'common control' in the context of the RMF?
- A security control inherited by multiple systems from a shared provider (Correct answer)
- A control applied only to classified systems
- A baseline control mandatory for all systems
- A control assessed by an external auditor
Correct answer: A security control inherited by multiple systems from a shared provider
Common controls are security controls whose implementation is managed at the organizational level and inherited by multiple information systems.
Question 6: Which document within the RMF authorization package identifies weaknesses and plans to remediate them?
- Plan of Action and Milestones (POA&M) (Correct answer)
- System Security Plan (SSP)
- Security Assessment Report (SAR)
- Authorization Decision Document
Correct answer: Plan of Action and Milestones (POA&M)
The POA&M tracks identified security weaknesses and documents the corrective actions and timelines for remediation.
Which FIPS standard defines the three security objectives: confidentiality, integrity, and availability?