CGRC · Question #114
The objective of status reporting & documentation is to ensure the Information System Owner updates the ____________ __________ and the POAM and that the security status is reported to the AO…
The correct answer is A. Security Plan. The question asks what key document, alongside the Plan of Action and Milestones (POAM), the Information System Owner (ISO) is responsible for updating during status reporting and documentation processes.
Question
The objective of status reporting & documentation is to ensure the Information System Owner updates the ____________ __________ and the POAM and that the security status is reported to the AO. Response:
Options
- ASecurity Plan
- BContingency Plan
- CAssessment Plan
- DRemediation plan
How the community answered
(17 responses)- A88% (15)
- B6% (1)
- C6% (1)
Why each option
The question asks what key document, alongside the Plan of Action and Milestones (POAM), the Information System Owner (ISO) is responsible for updating during status reporting and documentation processes.
The Security Plan is a foundational document that details a system's security controls and how they are implemented. Regular status reporting and documentation ensure that this plan, along with the Plan of Action and Milestones (POAM), remains current and reflects the system's ongoing security posture, which is then reported to the Authorizing Official (AO).
A Contingency Plan outlines procedures for incident response and disaster recovery, but it is not the primary document updated for general security status reporting.
An Assessment Plan details how security controls will be assessed, rather than the overall security status of the system itself.
A Remediation plan is generally part of the POAM or an outcome of an assessment, not a standalone document that the SO primarily updates for status reporting.
Concept tested: NIST RMF documentation and responsibilities
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-18r1.pdf
Topics
Community Discussion
No community discussion yet for this question.