nerdexam
(ISC)2

CAP · Question #306

Which of the following documents is used to provide a standard approach to the assessment of NIST SP 800-53 security controls?

The correct answer is C. NIST SP 800-53A. NIST SP 800-53A is titled 'Assessing Security and Privacy Controls in Information Systems and Organizations' and provides a standard methodology and assessment procedures for evaluating the effectiveness of the security controls defined in NIST SP 800-53. NIST SP 800-37 (A) is…

Assessment/Audit of Security and Privacy Controls

Question

Which of the following documents is used to provide a standard approach to the assessment of NIST SP 800-53 security controls?

Options

  • ANIST SP 800-37
  • BNIST SP 800-41
  • CNIST SP 800-53A
  • DNIST SP 800-66

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    94% (29)

Explanation

NIST SP 800-53A is titled 'Assessing Security and Privacy Controls in Information Systems and Organizations' and provides a standard methodology and assessment procedures for evaluating the effectiveness of the security controls defined in NIST SP 800-53. NIST SP 800-37 (A) is the Risk Management Framework guide. NIST SP 800-41 (B) covers guidelines on firewalls. NIST SP 800-66 (D) is a resource guide for implementing the HIPAA Security Rule. The 'A' suffix in 800-53A specifically denotes that it is the assessment companion to 800-53.

Topics

#NIST SP 800-53A#Security Control Assessment#NIST RMF#Compliance Assessment

Community Discussion

No community discussion yet for this question.

Full CAP Practice