CAP Security Authorization Documentation 2 — Questions and Answers
Question 1: What is the difference between an Authorization to Operate (ATO) and an Interim Authorization to Operate (IATO)?
- An ATO is a full authorization; an IATO is a time-limited authorization granted while residual risks are being mitigated (Correct answer)
- An ATO is for classified systems; an IATO is for unclassified systems
- An ATO requires FISMA compliance; an IATO does not
- An ATO is issued by the ISSO; an IATO is issued by the AO
Correct answer: An ATO is a full authorization; an IATO is a time-limited authorization granted while residual risks are being mitigated
An IATO allows a system to operate temporarily with known risks under conditions that must be remediated within a specified timeframe.
Question 2: What does an Authorization Denial (DATO) indicate?
- The AO has determined the risk is unacceptable and the system must not operate (Correct answer)
- The system passed all security controls but lacks documentation
- The ATO has expired and requires renewal
- The system has minor findings that need remediation
Correct answer: The AO has determined the risk is unacceptable and the system must not operate
A DATO means the Authorizing Official found the risk too high to accept and prohibits the system from operating.
Question 3: Which control family in NIST SP 800-53 specifically addresses planning and the System Security Plan?
- PL (Planning) (Correct answer)
- CA (Assessment, Authorization, and Monitoring)
- SA (System and Services Acquisition)
- RA (Risk Assessment)
Correct answer: PL (Planning)
The PL control family includes PL-2, which specifically requires the development and maintenance of the System Security Plan.
Question 4: How frequently must federal agencies review and update their System Security Plans per NIST guidance?
- At least annually or whenever significant changes occur (Correct answer)
- Every five years during reauthorization
- Only when a security incident occurs
- Quarterly regardless of system changes
Correct answer: At least annually or whenever significant changes occur
NIST recommends reviewing and updating the SSP at least annually and whenever significant changes to the system occur.
Question 5: What is the purpose of a Privacy Impact Assessment (PIA) in the authorization process?
- To identify and evaluate privacy risks associated with the collection or use of personally identifiable information (Correct answer)
- To assess physical security of server rooms
- To verify that encryption algorithms meet FIPS 140-2 standards
- To document user access rights and privileges
Correct answer: To identify and evaluate privacy risks associated with the collection or use of personally identifiable information
A PIA examines how PII is collected, used, shared, and protected to ensure compliance with privacy laws and mitigate privacy risks.
Question 6: Which NIST publication provides guidance on preparing the authorization package and submitting it to the AO?
- NIST SP 800-37 (Correct answer)
- NIST SP 800-53A
- NIST SP 800-30
- NIST SP 800-60
Correct answer: NIST SP 800-37
NIST SP 800-37 describes the RMF process including the preparation and submission of the authorization package to the Authorizing Official.
What is the difference between an Authorization to Operate (ATO) and an Interim Authorization to Operate (IATO)?