nerdexam
(ISC)2

CGRC · Question #162

Information developed from Federal Information Processing Standard (FIPS) 199 may be used as an input to which authorization package document? Response:

The correct answer is B. System security plan (SSP). FIPS 199 provides guidelines for categorizing information and information systems, and this categorization is a foundational input for developing the System Security Plan (SSP). The SSP documents the security controls for a system based on its security categorization.

Scope of the System

Question

Information developed from Federal Information Processing Standard (FIPS) 199 may be used as an input to which authorization package document? Response:

Options

  • ASecurity assessment report (SAR)
  • BSystem security plan (SSP)
  • CPlan of actions and milestones (POA&M)
  • DAuthorization decision document

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    89% (32)
  • C
    6% (2)
  • D
    3% (1)

Why each option

FIPS 199 provides guidelines for categorizing information and information systems, and this categorization is a foundational input for developing the System Security Plan (SSP). The SSP documents the security controls for a system based on its security categorization.

ASecurity assessment report (SAR)

The Security Assessment Report (SAR) documents the results of the security control assessment, which happens after the SSP is developed.

BSystem security plan (SSP)Correct

FIPS 199 defines the security categorization of information systems (low, moderate, high for confidentiality, integrity, availability). This categorization directly informs the selection and implementation of security controls documented in the System Security Plan (SSP), which is a core document in the authorization package. The SSP details the system boundaries, operational environment, and the security controls in place or planned.

CPlan of actions and milestones (POA&M)

The Plan of Actions and Milestones (POA&M) tracks weaknesses and deficiencies, which are identified after security controls are assessed, making it a subsequent document.

DAuthorization decision document

The Authorization Decision Document is the final document issued by the Authorizing Official, which comes after the SSP and SAR are completed and reviewed.

Concept tested: FIPS 199 and System Security Plan (SSP)

Source: https://csrc.nist.gov/glossary/term/federal_information_processing_standards_publication_199

Topics

#FIPS 199#System Security Plan (SSP)#Security Categorization#Risk Management Framework (RMF)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice