CGRC · Question #565
Of the ensuing potential inputs to the Authorization package, one is not a living document. Which one? Response:
The correct answer is A. Supporting assessment documents. Supporting assessment documents are generally not considered living documents as they are static records of evidence collected at a specific point in time during an assessment.
Question
Of the ensuing potential inputs to the Authorization package, one is not a living document. Which one? Response:
Options
- ASupporting assessment documents
- BPlan of Actions and Milestones (POA&Ms)
- CSecurity and Privacy Assessment Reports
- DSecurity and Privacy Plan
How the community answered
(25 responses)- A88% (22)
- B4% (1)
- D8% (2)
Why each option
Supporting assessment documents are generally not considered living documents as they are static records of evidence collected at a specific point in time during an assessment.
Supporting assessment documents, such as vulnerability scan results, audit logs, interview notes, or configuration snapshots, are artifacts collected during a specific assessment period. These documents represent a point-in-time record or evidence and are typically archived rather than continuously updated throughout the system's lifecycle, making them non-living documents.
Plans of Actions and Milestones (POA&Ms) are living documents that track deficiencies and their remediation, requiring continuous updates until all items are addressed.
Security and Privacy Assessment Reports are typically point-in-time snapshots of findings from an assessment, but 'supporting assessment documents' refers to the raw, underlying evidence which is even more definitively static.
A Security and Privacy Plan is a living document that outlines the system's security controls and is regularly reviewed and updated to reflect changes in the system, environment, or threat landscape.
Concept tested: Authorization package document types
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.