nerdexam
(ISC)2

CGRC · Question #565

Of the ensuing potential inputs to the Authorization package, one is not a living document. Which one? Response:

The correct answer is A. Supporting assessment documents. Supporting assessment documents are generally not considered living documents as they are static records of evidence collected at a specific point in time during an assessment.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Of the ensuing potential inputs to the Authorization package, one is not a living document. Which one? Response:

Options

  • ASupporting assessment documents
  • BPlan of Actions and Milestones (POA&Ms)
  • CSecurity and Privacy Assessment Reports
  • DSecurity and Privacy Plan

How the community answered

(25 responses)
  • A
    88% (22)
  • B
    4% (1)
  • D
    8% (2)

Why each option

Supporting assessment documents are generally not considered living documents as they are static records of evidence collected at a specific point in time during an assessment.

ASupporting assessment documentsCorrect

Supporting assessment documents, such as vulnerability scan results, audit logs, interview notes, or configuration snapshots, are artifacts collected during a specific assessment period. These documents represent a point-in-time record or evidence and are typically archived rather than continuously updated throughout the system's lifecycle, making them non-living documents.

BPlan of Actions and Milestones (POA&Ms)

Plans of Actions and Milestones (POA&Ms) are living documents that track deficiencies and their remediation, requiring continuous updates until all items are addressed.

CSecurity and Privacy Assessment Reports

Security and Privacy Assessment Reports are typically point-in-time snapshots of findings from an assessment, but 'supporting assessment documents' refers to the raw, underlying evidence which is even more definitively static.

DSecurity and Privacy Plan

A Security and Privacy Plan is a living document that outlines the system's security controls and is regularly reviewed and updated to reflect changes in the system, environment, or threat landscape.

Concept tested: Authorization package document types

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Authorization Package#Living Documents#RMF Documents#NIST RMF

Community Discussion

No community discussion yet for this question.

Full CGRC Practice