CAP CAP Security Documentation & Authorization Artifacts 4 — Questions and Answers
Question 1: Which document in the RMF authorization package formally describes the boundary of the information system being assessed?
- System Security Plan (SSP) (Correct answer)
- Privacy Impact Assessment (PIA)
- Security Assessment Report (SAR)
- Plan of Action and Milestones (POA&M)
Correct answer: System Security Plan (SSP)
The SSP defines the authorization boundary, system description, and security controls implemented for the information system.
Question 2: When an inherited control does not fully satisfy a system's security requirements, what artifact documents the system-specific additions needed?
- Control correlation identifier (CCI)
- Control implementation statement supplement (Correct answer)
- Security assessment procedure
- Common control authorization letter
Correct answer: Control implementation statement supplement
A control implementation statement supplement documents how the inheriting system fills gaps left by a partially inherited common control.
Question 3: Which NIST document provides the standardized format and content requirements for Security Assessment Reports?
- NIST SP 800-37
- NIST SP 800-53A (Correct answer)
- NIST SP 800-60
- NIST SP 800-137
Correct answer: NIST SP 800-53A
NIST SP 800-53A provides assessment procedures and guidance on documenting findings in the Security Assessment Report.
Question 4: An organization discovers a critical vulnerability after the ATO is issued. Which authorization artifact must be IMMEDIATELY updated?
- System Security Plan
- Security Assessment Report
- Plan of Action and Milestones (POA&M) (Correct answer)
- Authorization Decision Document
Correct answer: Plan of Action and Milestones (POA&M)
The POA&M must be updated immediately to document the newly discovered vulnerability, its risk level, and planned remediation timeline.
Question 5: What is the primary purpose of the Authorization Decision Document signed by the Authorizing Official?
- Authorize the use of a specific encryption algorithm
- Formally accept residual risk and grant or deny system operation (Correct answer)
- Assign security control responsibilities to system owners
- Document the results of penetration testing activities
Correct answer: Formally accept residual risk and grant or deny system operation
The Authorization Decision Document (ADD) is the AO's formal statement accepting residual risk and granting, denying, or conditionally granting ATO.
Question 6: Which section of the System Security Plan (SSP) would describe how a system handles personally identifiable information (PII)?
- System operating environment
- Privacy considerations and Privacy Impact Assessment reference (Correct answer)
- Interconnection agreements section
- Security categorization rationale
Correct answer: Privacy considerations and Privacy Impact Assessment reference
The SSP references privacy considerations and links to the Privacy Impact Assessment when the system processes PII.
Question 7: What distinguishes a Memorandum of Understanding (MOU) from an Interconnection Security Agreement (ISA) as authorization artifacts?
- MOUs are legally binding; ISAs are informal agreements
- ISAs detail technical/security requirements for connections; MOUs define organizational responsibilities (Correct answer)
- ISAs are required for cloud connections only; MOUs cover on-premises links
- MOUs replace ISAs when systems share the same ISSO
Correct answer: ISAs detail technical/security requirements for connections; MOUs define organizational responsibilities
An ISA documents the technical and security requirements governing a specific interconnection, while an MOU defines the broader organizational roles and responsibilities.
Which document in the RMF authorization package formally describes the boundary of the information system being assessed?