CAP Security Control Assessment & Security Assessment Reports (SAR) — Questions and Answers
Question 1: Which NIST publication provides the methodology for assessing the effectiveness of security controls in federal information systems?
- NIST SP 800-37
- NIST SP 800-53A (Correct answer)
- NIST SP 800-60
- NIST SP 800-137
Correct answer: NIST SP 800-53A
NIST SP 800-53A ('Assessing Security and Privacy Controls in Information Systems and Organizations') provides the procedures for assessing each control in NIST SP 800-53. It defines assessment methods (examine, interview, test) and procedures aligned to each control.
Question 2: NIST SP 800-53A defines three assessment methods. Which set correctly identifies all three?
- Scan, Analyze, Report
- Examine, Interview, Test (Correct answer)
- Observe, Document, Verify
- Review, Audit, Penetrate
Correct answer: Examine, Interview, Test
NIST SP 800-53A defines three assessment methods: Examine (reviewing documentation and artifacts), Interview (discussing controls with personnel), and Test (exercising the control through technical or operational means). These three methods together provide comprehensive coverage of control effectiveness.
Question 3: What is the primary output document produced at the conclusion of a security control assessment?
- System Security Plan (SSP)
- Plan of Action and Milestones (POA&M)
- Security Assessment Report (SAR) (Correct answer)
- Authorization to Operate (ATO) letter
Correct answer: Security Assessment Report (SAR)
The Security Assessment Report (SAR) documents the assessor's findings, including which controls are effective (satisfied), which are partially effective (other than satisfied), and which are ineffective (not satisfied). The SAR is a key input to the authorization decision.
Question 4: Why is assessor independence important in the security control assessment process?
- It ensures the assessor has no financial interest in the organization being assessed.
- It prevents conflicts of interest where the assessor might overlook deficiencies in controls they helped implement. (Correct answer)
- It is required so that assessors can hold a Top Secret clearance.
- It ensures the assessment is completed faster by using a dedicated team.
Correct answer: It prevents conflicts of interest where the assessor might overlook deficiencies in controls they helped implement.
Assessor independence (as described in NIST SP 800-37 and SP 800-53A) is critical because individuals who designed or implemented controls have an inherent conflict of interest when assessing those same controls. Independent assessment provides objective, unbiased results for the AO's decision.
Question 5: After a security assessment identifies control weaknesses that cannot be immediately remediated, what document is used to track the planned remediation actions?
- Security Assessment Report (SAR)
- System Security Plan (SSP)
- Plan of Action and Milestones (POA&M) (Correct answer)
- Risk Assessment Report (RAR)
Correct answer: Plan of Action and Milestones (POA&M)
The Plan of Action and Milestones (POA&M) is the formal document used to track identified weaknesses, the actions planned to correct them, the resources required, and the target completion dates. The POA&M is reviewed by the AO as part of the authorization package.
Question 6: Which of the following items is NOT typically included in an authorization package submitted to the Authorizing Official?
- System Security Plan (SSP)
- Security Assessment Report (SAR)
- Plan of Action and Milestones (POA&M)
- Penetration Test Scope Agreement (Correct answer)
Correct answer: Penetration Test Scope Agreement
The standard authorization package per NIST SP 800-37 consists of three core documents: the SSP, the SAR, and the POA&M. A penetration test scope agreement is a pre-engagement document used in contracting, not a formal component of the authorization package.
Which NIST publication provides the methodology for assessing the effectiveness of security controls in federal information systems?