nerdexam
(ISC)2

CAP · Question #128

FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that…

The correct answer is E. Level 3. FITSAF Level 3 indicates that security procedures and controls have been formally implemented, moving beyond documentation to actual deployment.

Implementation of Security and Privacy Controls

Question

FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls have been implemented?

Options

  • ALevel 2
  • BLevel 5
  • CLevel 4
  • DLevel 1
  • ELevel 3

How the community answered

(39 responses)
  • B
    3% (1)
  • C
    3% (1)
  • E
    95% (37)

Why each option

FITSAF Level 3 indicates that security procedures and controls have been formally implemented, moving beyond documentation to actual deployment.

ALevel 2

FITSAF Level 2 indicates that procedures and controls are documented, but not yet implemented.

BLevel 5

FITSAF Level 5 represents full integration of procedures and controls into a comprehensive security program with continuous improvement.

CLevel 4

FITSAF Level 4 indicates that procedures and controls have been tested and reviewed, which goes beyond mere implementation.

DLevel 1

FITSAF Level 1 indicates that an information security policy exists but procedures are not yet documented or implemented.

ELevel 3Correct

In the Federal Information Technology Security Assessment Framework, Level 3 specifically represents the stage where documented procedures and controls have been implemented within the organization's systems. This level sits between Level 2 (procedures and controls documented) and Level 4 (procedures and controls tested and reviewed), marking the transition from paper-based policy to operational reality. Reaching Level 3 demonstrates that security requirements are actively applied, not merely recorded.

Concept tested: FITSAF maturity level definitions

Source: https://csrc.nist.gov/publications/detail/sp/800-26/final

Topics

#FITSAF#Control Implementation#Security Control Levels#Security Assessment Frameworks

Community Discussion

No community discussion yet for this question.

Full CAP Practice