nerdexam
(ISC)2

CGRC · Question #420

The security authorization package contains multiple key documents enabling the authorization officials to make risk based authorization decisions. Which of the following documents is not part of…

The correct answer is D. The security service level agreements. Security Service Level Agreements (SLAs) define performance expectations and responsibilities between parties, but they are not a core component of the security authorization package, which focuses on the system's security posture and risk acceptance.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The security authorization package contains multiple key documents enabling the authorization officials to make risk based authorization decisions. Which of the following documents is not part of the package? Response:

Options

  • AThe security plan
  • BThe security assessment report
  • CThe plan of action and milestones
  • DThe security service level agreements

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • D
    93% (26)

Why each option

Security Service Level Agreements (SLAs) define performance expectations and responsibilities between parties, but they are not a core component of the security authorization package, which focuses on the system's security posture and risk acceptance.

AThe security plan

The security plan describes the security controls for the system and is a fundamental component of the authorization package.

BThe security assessment report

The security assessment report details the findings from the security control assessment and is critical for informing the authorization decision.

CThe plan of action and milestones

The Plan of Action and Milestones (POAM) identifies and tracks the remediation of security weaknesses and is a vital document for managing residual risk within the authorization process.

DThe security service level agreementsCorrect

Security Service Level Agreements (SLAs) are contracts or agreements that define the level of service expected from a service provider, including security-related metrics. While important for operational security, SLAs are generally not a mandatory part of the formal security authorization package submitted to an authorizing official for a risk-based decision.

Concept tested: Security Authorization Package (RMF) components

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Authorization Package#Risk Management Framework#Authorization to Operate (ATO)#Security Documentation

Community Discussion

No community discussion yet for this question.

Full CGRC Practice