CGRC · Question #420
The security authorization package contains multiple key documents enabling the authorization officials to make risk based authorization decisions. Which of the following documents is not part of…
The correct answer is D. The security service level agreements. Security Service Level Agreements (SLAs) define performance expectations and responsibilities between parties, but they are not a core component of the security authorization package, which focuses on the system's security posture and risk acceptance.
Question
The security authorization package contains multiple key documents enabling the authorization officials to make risk based authorization decisions. Which of the following documents is not part of the package? Response:
Options
- AThe security plan
- BThe security assessment report
- CThe plan of action and milestones
- DThe security service level agreements
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- D93% (26)
Why each option
Security Service Level Agreements (SLAs) define performance expectations and responsibilities between parties, but they are not a core component of the security authorization package, which focuses on the system's security posture and risk acceptance.
The security plan describes the security controls for the system and is a fundamental component of the authorization package.
The security assessment report details the findings from the security control assessment and is critical for informing the authorization decision.
The Plan of Action and Milestones (POAM) identifies and tracks the remediation of security weaknesses and is a vital document for managing residual risk within the authorization process.
Security Service Level Agreements (SLAs) are contracts or agreements that define the level of service expected from a service provider, including security-related metrics. While important for operational security, SLAs are generally not a mandatory part of the formal security authorization package submitted to an authorizing official for a risk-based decision.
Concept tested: Security Authorization Package (RMF) components
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.