CGRC · Question #162
Information developed from Federal Information Processing Standard (FIPS) 199 may be used as an input to which authorization package document? Response:
The correct answer is B. System security plan (SSP). FIPS 199 provides guidelines for categorizing information and information systems, and this categorization is a foundational input for developing the System Security Plan (SSP). The SSP documents the security controls for a system based on its security categorization.
Question
Information developed from Federal Information Processing Standard (FIPS) 199 may be used as an input to which authorization package document? Response:
Options
- ASecurity assessment report (SAR)
- BSystem security plan (SSP)
- CPlan of actions and milestones (POA&M)
- DAuthorization decision document
How the community answered
(36 responses)- A3% (1)
- B89% (32)
- C6% (2)
- D3% (1)
Why each option
FIPS 199 provides guidelines for categorizing information and information systems, and this categorization is a foundational input for developing the System Security Plan (SSP). The SSP documents the security controls for a system based on its security categorization.
The Security Assessment Report (SAR) documents the results of the security control assessment, which happens after the SSP is developed.
FIPS 199 defines the security categorization of information systems (low, moderate, high for confidentiality, integrity, availability). This categorization directly informs the selection and implementation of security controls documented in the System Security Plan (SSP), which is a core document in the authorization package. The SSP details the system boundaries, operational environment, and the security controls in place or planned.
The Plan of Actions and Milestones (POA&M) tracks weaknesses and deficiencies, which are identified after security controls are assessed, making it a subsequent document.
The Authorization Decision Document is the final document issued by the Authorizing Official, which comes after the SSP and SAR are completed and reviewed.
Concept tested: FIPS 199 and System Security Plan (SSP)
Source: https://csrc.nist.gov/glossary/term/federal_information_processing_standards_publication_199
Topics
Community Discussion
No community discussion yet for this question.