nerdexam
(ISC)2

CGRC · Question #289

What essential documentation should be included in the system authorization package? Response:

The correct answer is A. System security plan B. Risk assessment (which includes a minimum security baseline assessment, and which may be an C. Certification test plan and results report (might also be referred to as a security assessment report) D. Remediation plan (or plan of action and milestones) E. Certification statement. A system authorization package must include key documents like the System Security Plan, Risk Assessment, Security Assessment Report, Remediation Plan, and Certification Statement to facilitate the authorization decision.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What essential documentation should be included in the system authorization package? Response:

Options

  • ASystem security plan
  • BRisk assessment (which includes a minimum security baseline assessment, and which may be an
  • CCertification test plan and results report (might also be referred to as a security assessment report)
  • DRemediation plan (or plan of action and milestones)
  • ECertification statement
  • FRequirement analysis
  • GExecution plan
  • HSystem impact analysis

How the community answered

(26 responses)
  • A
    88% (23)
  • F
    8% (2)
  • H
    4% (1)

Why each option

A system authorization package must include key documents like the System Security Plan, Risk Assessment, Security Assessment Report, Remediation Plan, and Certification Statement to facilitate the authorization decision.

ASystem security planCorrect

According to frameworks like NIST RMF, the authorization package is a comprehensive set of documents providing evidence of the system's security posture. It typically includes the System Security Plan, detailing controls; the Risk Assessment, identifying and analyzing risks; the Security Assessment Report, documenting test results; the Plan of Action and Milestones (POAM) or Remediation Plan, outlining corrective actions; and a formal Authorization (or Certification) Statement by the authorizing official.

BRisk assessment (which includes a minimum security baseline assessment, and which may be anCorrect

According to frameworks like NIST RMF, the authorization package is a comprehensive set of documents providing evidence of the system's security posture. It typically includes the System Security Plan, detailing controls; the Risk Assessment, identifying and analyzing risks; the Security Assessment Report, documenting test results; the Plan of Action and Milestones (POAM) or Remediation Plan, outlining corrective actions; and a formal Authorization (or Certification) Statement by the authorizing official.

CCertification test plan and results report (might also be referred to as a security assessment report)Correct

According to frameworks like NIST RMF, the authorization package is a comprehensive set of documents providing evidence of the system's security posture. It typically includes the System Security Plan, detailing controls; the Risk Assessment, identifying and analyzing risks; the Security Assessment Report, documenting test results; the Plan of Action and Milestones (POAM) or Remediation Plan, outlining corrective actions; and a formal Authorization (or Certification) Statement by the authorizing official.

DRemediation plan (or plan of action and milestones)Correct

According to frameworks like NIST RMF, the authorization package is a comprehensive set of documents providing evidence of the system's security posture. It typically includes the System Security Plan, detailing controls; the Risk Assessment, identifying and analyzing risks; the Security Assessment Report, documenting test results; the Plan of Action and Milestones (POAM) or Remediation Plan, outlining corrective actions; and a formal Authorization (or Certification) Statement by the authorizing official.

ECertification statementCorrect

According to frameworks like NIST RMF, the authorization package is a comprehensive set of documents providing evidence of the system's security posture. It typically includes the System Security Plan, detailing controls; the Risk Assessment, identifying and analyzing risks; the Security Assessment Report, documenting test results; the Plan of Action and Milestones (POAM) or Remediation Plan, outlining corrective actions; and a formal Authorization (or Certification) Statement by the authorizing official.

FRequirement analysis

Requirement analysis is an earlier SDLC phase input, not a core component of the final authorization package.

GExecution plan

An Execution plan is a broader project management document, not specifically part of the security authorization package.

HSystem impact analysis

System impact analysis is often part of risk assessment or BIA, but not typically a separate core document in the authorization package itself.

Concept tested: System authorization package contents (NIST RMF)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#System Authorization Package#RMF Authorization#Authorization Documentation#System Security Plan

Community Discussion

No community discussion yet for this question.

Full CGRC Practice