312-50V11 · Question #81
Which regulation defines security and privacy controls for Federal information systems and organizations?
The correct answer is D. NIST-800-53. NIST SP 800-53 is the authoritative federal standard defining security and privacy controls for U.S. federal information systems and organizations.
Question
Which regulation defines security and privacy controls for Federal information systems and organizations?
Options
- AHIPAA
- BEU Safe Harbor
- CPCI-DSS
- DNIST-800-53
How the community answered
(33 responses)- A3% (1)
- B6% (2)
- D91% (30)
Why each option
NIST SP 800-53 is the authoritative federal standard defining security and privacy controls for U.S. federal information systems and organizations.
HIPAA defines security and privacy requirements specifically for protected health information in the healthcare sector, not federal information systems broadly.
EU Safe Harbor was a framework governing commercial data transfers between the European Union and the United States and did not define security controls for federal systems.
PCI-DSS defines security controls for organizations that store, process, or transmit payment card data and has no federal government mandate.
NIST SP 800-53 was developed by the National Institute of Standards and Technology and is mandated for federal agencies under FISMA (Federal Information Security Management Act). It provides a comprehensive catalog of security and privacy controls organized into families such as Access Control, Audit and Accountability, and Incident Response, forming the foundation of federal cybersecurity compliance.
Concept tested: NIST 800-53 federal security controls framework
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.