nerdexam
(ISC)2

CAP · Question #343

FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that…

The correct answer is C. Level 4. FITSAF (Federal Information Technology Security Assessment Framework) defines five progressive maturity levels: Level 1 - Documented policy exists; Level 2 - Documented procedures exist; Level 3 - Procedures and controls are implemented; Level 4 - Procedures and controls are…

Assessment/Audit of Security and Privacy Controls

Question

FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls are tested and reviewed?

Options

  • ALevel 1
  • BLevel 2
  • CLevel 4
  • DLevel 5
  • ELevel 3

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    89% (39)
  • D
    7% (3)

Explanation

FITSAF (Federal Information Technology Security Assessment Framework) defines five progressive maturity levels: Level 1 - Documented policy exists; Level 2 - Documented procedures exist; Level 3 - Procedures and controls are implemented; Level 4 - Procedures and controls are tested and reviewed; Level 5 - Procedures and controls are fully integrated into a comprehensive program. The question asks for the level where testing and review occur, which is Level 4. Answer choice C corresponds to Level 4 in the option list provided (A=Level 1, B=Level 2, C=Level 4, D=Level 5, E=Level 3).

Topics

#FITSAF#Security Assessment#Control Testing#Maturity Models

Community Discussion

No community discussion yet for this question.

Full CAP Practice