CAP CAP Security Documentation & Authorization Artifacts 5 — Questions and Answers
Question 1: In a continuous monitoring program, how frequently must POA&M entries be reviewed at minimum according to NIST guidance?
- Weekly
- Monthly (Correct answer)
- Quarterly
- Annually
Correct answer: Monthly
NIST SP 800-137 recommends monthly POA&M reviews as part of ongoing authorization and continuous monitoring activities.
Question 2: Which artifact specifically documents the agreement between a cloud service provider and a federal agency regarding shared security responsibilities?
- FedRAMP Authorization Package
- Customer Responsibility Matrix (CRM) (Correct answer)
- Service Level Agreement (SLA)
- Interconnection Security Agreement (ISA)
Correct answer: Customer Responsibility Matrix (CRM)
The Customer Responsibility Matrix (also called Shared Responsibility Matrix) explicitly delineates which security controls are managed by the CSP versus the agency.
Question 3: A system owner wants to reuse security assessment results from a similar system assessed 14 months ago. What is the primary concern with this approach?
- Assessment results cannot legally be reused across different systems
- The previous SAR may be outside the acceptable reuse window, typically 12 months (Correct answer)
- Security assessors must be the same personnel for reuse to be valid
- Reuse is only permitted for systems with the same data classification
Correct answer: The previous SAR may be outside the acceptable reuse window, typically 12 months
NIST guidance generally limits reuse of assessment evidence to within 12 months, as older results may not reflect the current security posture.
Question 4: Which document would an ISSO reference to determine the specific assessment methods (examine, interview, test) required for each security control?
- NIST SP 800-53 Revision 5
- NIST SP 800-53A Revision 5 (Correct answer)
- NIST SP 800-37 Revision 2
- FIPS 199
Correct answer: NIST SP 800-53A Revision 5
NIST SP 800-53A provides the assessment procedures, including whether each control requires examination of artifacts, interviews with personnel, or technical testing.
Question 5: What is the purpose of including a 'control origination' field in the SSP control implementation statements?
- Identify the vendor who developed the security control technology
- Indicate whether a control is system-specific, hybrid, inherited, or common (Correct answer)
- Record the date the control was first implemented
- Specify the regulatory framework that mandates the control
Correct answer: Indicate whether a control is system-specific, hybrid, inherited, or common
The control origination field clarifies accountability by showing whether a control is implemented locally, shared with a common control provider, or a hybrid arrangement.
Question 6: When preparing an authorization package for a system with a HIGH confidentiality impact level, which additional artifact is typically required compared to a MODERATE system?
- A separate Business Impact Analysis (BIA)
- More rigorous penetration test results documented in the SAR (Correct answer)
- An additional privacy threshold analysis
- A physical security plan addendum
Correct answer: More rigorous penetration test results documented in the SAR
HIGH-impact systems typically require more rigorous independent security testing, with detailed penetration test findings documented within or appended to the Security Assessment Report.
Question 7: Under RMF, which artifact serves as the 'living document' that must be updated throughout the system lifecycle, not just at authorization time?
- Authorization Decision Document
- Security Categorization memo
- System Security Plan (SSP) (Correct answer)
- Initial Risk Assessment
Correct answer: System Security Plan (SSP)
The SSP is a living document that must be kept current throughout the system's lifecycle, updated whenever significant changes occur or controls are modified.
In a continuous monitoring program, how frequently must POA&M entries be reviewed at minimum according to NIST guidance?