CAP · Question #264
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that…
The correct answer is C. Level 3. FITSAF Level 3 indicates that the documented security procedures and controls have actually been implemented within the information system.
Question
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls have been implemented?
Options
- ALevel 4
- BLevel 1
- CLevel 3
- DLevel 5
- ELevel 2
How the community answered
(20 responses)- A5% (1)
- C90% (18)
- E5% (1)
Why each option
FITSAF Level 3 indicates that the documented security procedures and controls have actually been implemented within the information system.
Level 4 represents that procedures and controls have been tested and reviewed for effectiveness, going beyond mere implementation.
Level 1 represents that an information security policy has been documented, not that controls are implemented.
In the FITSAF five-level maturity model, Level 3 specifically represents the stage where security procedures and controls are not only documented but have been fully implemented and are operational. Levels 1 and 2 cover documented policies and procedures respectively, while Levels 4 and 5 cover testing/review and full integration respectively.
Level 5 represents that security procedures are fully integrated into a comprehensive program with continuous improvement.
Level 2 represents that procedures are documented to fulfill the policy, not yet implemented.
Concept tested: FITSAF security maturity levels
Source: https://csrc.nist.gov/publications/detail/sp/800-26/final
Topics
Community Discussion
No community discussion yet for this question.