CGRC · Question #705
Which of the following are the objectives of the security certification documentation task? Each correct answer represents a complete solution. Choose all that apply. Response:
The correct answer is A. To prepare the Plan of Action and Milestones (POAM) based on the security assessment B. To provide the certification findings and recommendations to the information system owner C. To assemble the final security accreditation package and then submit it to the authorizing o fficial D. To update the system security plan based on the results of the security assessment. The security certification documentation task involves a comprehensive set of objectives including preparing remediation plans, reporting findings, compiling accreditation packages, and updating system security plans.
Question
Which of the following are the objectives of the security certification documentation task? Each correct answer represents a complete solution. Choose all that apply. Response:
Options
- ATo prepare the Plan of Action and Milestones (POAM) based on the security assessment
- BTo provide the certification findings and recommendations to the information system owner
- CTo assemble the final security accreditation package and then submit it to the authorizing o fficial
- DTo update the system security plan based on the results of the security assessment
How the community answered
(52 responses)- A100% (52)
Why each option
The security certification documentation task involves a comprehensive set of objectives including preparing remediation plans, reporting findings, compiling accreditation packages, and updating system security plans.
Based on the security assessment, a Plan of Action and Milestones (POAM) is prepared to track and manage the remediation of identified vulnerabilities and weaknesses.
Providing certification findings and recommendations to the information system owner is crucial for transparency and informed decision-making regarding the system's security posture.
Assembling the final security accreditation package for submission to the authorizing official is a key objective to enable an informed authorization decision.
Updating the system security plan is essential to reflect the current security state, implemented controls, and any changes or remediation actions resulting from the security assessment.
Concept tested: Objectives of security certification documentation
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev2/final
Topics
Community Discussion
No community discussion yet for this question.