CGRC · Question #479
Which document in support of the authorization package contains the well-defined set of security controls for an information system? Response:
The correct answer is B. System Security Plan (SSP). The System Security Plan (SSP) is the document in an authorization package that contains the detailed set of security controls for an information system.
Question
Which document in support of the authorization package contains the well-defined set of security controls for an information system? Response:
Options
- AInitial Risk Assessment
- BSystem Security Plan (SSP)
- CSecurity and Privacy assessment reports
- DPlan of Action and Milestones (POA&M)
How the community answered
(28 responses)- B96% (27)
- D4% (1)
Why each option
The System Security Plan (SSP) is the document in an authorization package that contains the detailed set of security controls for an information system.
An Initial Risk Assessment identifies potential risks and vulnerabilities but does not define the comprehensive set of implemented security controls.
The System Security Plan (SSP) is a foundational document within the authorization package that comprehensively describes the security controls chosen and implemented for an information system. It outlines how the system meets specific security requirements, detailing the technical, management, and operational controls to protect the system and its data.
Security and Privacy assessment reports document the results of security control evaluations, not the plan of controls themselves.
A Plan of Action and Milestones (POA&M) outlines tasks and deadlines for addressing identified security weaknesses, not the complete set of operational controls.
Concept tested: System Security Plan (SSP) role
Source: csrc.nist.gov/publications/detail/sp/800-18/rev-1/archive/2006-02-14
Topics
Community Discussion
No community discussion yet for this question.