nerdexam
(ISC)2

CGRC · Question #479

Which document in support of the authorization package contains the well-defined set of security controls for an information system? Response:

The correct answer is B. System Security Plan (SSP). The System Security Plan (SSP) is the document in an authorization package that contains the detailed set of security controls for an information system.

Selection and Approval of Framework, Security, and Privacy Controls

Question

Which document in support of the authorization package contains the well-defined set of security controls for an information system? Response:

Options

  • AInitial Risk Assessment
  • BSystem Security Plan (SSP)
  • CSecurity and Privacy assessment reports
  • DPlan of Action and Milestones (POA&M)

How the community answered

(28 responses)
  • B
    96% (27)
  • D
    4% (1)

Why each option

The System Security Plan (SSP) is the document in an authorization package that contains the detailed set of security controls for an information system.

AInitial Risk Assessment

An Initial Risk Assessment identifies potential risks and vulnerabilities but does not define the comprehensive set of implemented security controls.

BSystem Security Plan (SSP)Correct

The System Security Plan (SSP) is a foundational document within the authorization package that comprehensively describes the security controls chosen and implemented for an information system. It outlines how the system meets specific security requirements, detailing the technical, management, and operational controls to protect the system and its data.

CSecurity and Privacy assessment reports

Security and Privacy assessment reports document the results of security control evaluations, not the plan of controls themselves.

DPlan of Action and Milestones (POA&M)

A Plan of Action and Milestones (POA&M) outlines tasks and deadlines for addressing identified security weaknesses, not the complete set of operational controls.

Concept tested: System Security Plan (SSP) role

Source: csrc.nist.gov/publications/detail/sp/800-18/rev-1/archive/2006-02-14

Topics

#System Security Plan (SSP)#Authorization Package#Security Controls#Risk Management Framework (RMF)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice