SFPC - Security Fundamentals Professional Risk Management Framework Questions and Answers 1 — Questions and Answers
Question 1: An information system has been through the 'Assess' step of the Risk Management Framework (RMF). The assessment found several non-compliant security controls. What is the primary purpose of the Plan of Action and Milestones (POA&M) document created at this stage?
- To serve as the formal authorization decision for the system to operate.
- To provide a detailed technical description of the system's architecture and boundaries.
- To document the system's information categorization and impact levels.
- To track the tasks, resources, and timelines required to correct identified weaknesses. (Correct answer)
Correct answer: To track the tasks, resources, and timelines required to correct identified weaknesses.
The Plan of Action and Milestones (POA&M) is a corrective action plan used to track and manage the remediation of security weaknesses and vulnerabilities identified during a security control assessment. It details the specific tasks, necessary resources, milestones, and completion dates for addressing non-compliant controls.
Question 2: A senior management official is presented with an authorization package that includes the System Security Plan (SSP), the Security Assessment Report (SAR), and a Plan of Action and Milestones (POA&M). By signing the Authorization to Operate (ATO), what is this official formally doing?
- Certifying that all security controls have been implemented perfectly.
- Accepting the remaining residual risk of operating the information system. (Correct answer)
- Approving the budget for the next three years of security operations.
- Confirming that all items in the POA&M have been fully remediated.
Correct answer: Accepting the remaining residual risk of operating the information system.
The 'Authorize' step of the RMF culminates in a senior official, the Authorizing Official (AO), making a formal decision. By granting an Authorization to Operate (ATO), the AO is formally accepting the security and privacy risk to the organization based on the implementation of controls and the plan to address remaining weaknesses, which is known as residual risk.
Question 3: Which RMF step involves determining the potential impact on confidentiality, integrity, and availability of an information system and its data if there were a security breach?
- Select
- Assess
- Categorize (Correct answer)
- Monitor
Correct answer: Categorize
The 'Categorize' step is the part of the RMF where the system and the information it processes are evaluated based on the potential impact of a loss of confidentiality, integrity, and availability. This categorization (e.g., as Low, Moderate, or High impact) informs the selection of appropriate security controls in the next step.
Question 4: A system owner is preparing the key documentation for a new information system undergoing the RMF process. Which document provides a detailed overview of the security requirements and describes the specific controls in place or planned to meet those requirements?
- Plan of Action and Milestones (POA&M)
- Security Assessment Report (SAR)
- Authorization to Operate (ATO)
- System Security Plan (SSP) (Correct answer)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) is the formal document that provides a comprehensive overview of a system's security requirements and details the security controls implemented or planned to meet them. It is a foundational document in the authorization package.
Question 5: During which step of the Risk Management Framework are security controls actually installed, configured, and integrated into the information system?
- Select
- Implement (Correct answer)
- Assess
- Authorize
Correct answer: Implement
The 'Implement' step is the phase of the RMF where the security controls selected in the previous step are put into practice. This involves the practical application and configuration of technical safeguards and the establishment of non-technical processes.
Question 6: Which of the following activities is the primary focus of the 'Monitor' step in the Risk Management Framework?
- Performing the initial authorization of the system.
- Selecting the initial baseline of security controls.
- Continuously tracking changes to the system and assessing control effectiveness over time. (Correct answer)
- Developing the initial System Security Plan (SSP).
Correct answer: Continuously tracking changes to the system and assessing control effectiveness over time.
The 'Monitor' step is the final, ongoing phase of the RMF. Its purpose is to maintain security posture by continuously monitoring control implementation, assessing for changes, and understanding the ongoing risk to the system. This ensures that security remains effective throughout the system's lifecycle.
An information system has been through the 'Assess' step of the Risk Management Framework (RMF).
The assessment found several non-compliant security controls.
What is the primary purpose of the Plan of Action and Milestones (POA&M) document created at this stage?