CAP Security Authorization Documentation 1 — Questions and Answers
Question 1: What is the primary purpose of a System Security Plan (SSP)?
- To describe security requirements and document controls implemented for an information system (Correct answer)
- To list all software vulnerabilities found during testing
- To track remediation milestones for security weaknesses
- To define the organization's overall security policy
Correct answer: To describe security requirements and document controls implemented for an information system
The SSP is the central document describing system characteristics, the security environment, and how controls are implemented.
Question 2: Which artifact in the authorization package summarizes the findings from security control testing?
- Security Assessment Report (SAR) (Correct answer)
- System Security Plan (SSP)
- POA&M
- Authorization Decision Document
Correct answer: Security Assessment Report (SAR)
The SAR documents the results of the security assessment, including findings, evidence, and recommendations.
Question 3: What are the three core documents that make up a standard RMF authorization package?
- SSP, SAR, and POA&M (Correct answer)
- SSP, ATO, and FIPS 199
- SAR, POA&M, and ATO
- FIPS 199, SSP, and SAR
Correct answer: SSP, SAR, and POA&M
The authorization package submitted to the AO consists of the System Security Plan, Security Assessment Report, and Plan of Action and Milestones.
Question 4: What information must a System Security Plan include about the system boundary?
- A description of the authorization boundary defining which components are within scope (Correct answer)
- Only the IP addresses of networked devices
- The physical location of all servers
- A list of all user account names
Correct answer: A description of the authorization boundary defining which components are within scope
The SSP must clearly define the authorization boundary to establish what hardware, software, and services are in scope for the assessment.
Question 5: Which section of the SSP typically describes how the system processes, stores, or transmits federal information?
- System Description / Operational Environment (Correct answer)
- Control Implementation Summary
- POA&M Appendix
- Authorization Decision
Correct answer: System Description / Operational Environment
The system description section explains the system's purpose, data flows, and operational context including what information it handles.
Question 6: What does the term 'authorization boundary' mean in the context of an SSP?
- The logical or physical perimeter defining all system components under a single ATO (Correct answer)
- The network perimeter defended by a firewall
- The organizational boundary between agencies
- The scope of a penetration test
Correct answer: The logical or physical perimeter defining all system components under a single ATO
The authorization boundary encompasses all system components—hardware, software, firmware, and people—included under one authorization decision.
What is the primary purpose of a System Security Plan (SSP)?