nerdexam
(ISC)2

CAP · Question #227

Which of the following documents is used to provide a standard approach to the assessment of NIST SP 800-53 security controls?

The correct answer is A. NIST SP 800-53A. NIST SP 800-53A (Assessing Security and Privacy Controls in Information Systems and Organizations) provides a standardized, repeatable methodology for assessing the security controls defined in NIST SP 800-53. It contains detailed assessment procedures, objectives, and methods…

Assessment/Audit of Security and Privacy Controls

Question

Which of the following documents is used to provide a standard approach to the assessment of NIST SP 800-53 security controls?

Options

  • ANIST SP 800-53A
  • BNIST SP 800-66
  • CNIST SP 800-41
  • DNIST SP 800-37

How the community answered

(67 responses)
  • A
    88% (59)
  • B
    1% (1)
  • C
    3% (2)
  • D
    7% (5)

Explanation

NIST SP 800-53A (Assessing Security and Privacy Controls in Information Systems and Organizations) provides a standardized, repeatable methodology for assessing the security controls defined in NIST SP 800-53. It contains detailed assessment procedures, objectives, and methods (examine, interview, test) for each control. NIST SP 800-66 addresses HIPAA security rule implementation, SP 800-41 covers firewall guidelines, and SP 800-37 describes the Risk Management Framework (RMF) process - none of these provide the control-by-control assessment procedures that SP 800-53A does.

Topics

#NIST SP 800-53A#Security Control Assessment#Assessment Methodology#NIST SP 800-53

Community Discussion

No community discussion yet for this question.

Full CAP Practice