nerdexam
(ISC)2

CAP · Question #77

Which of the following is a standard that sets basic requirements for assessing the effectiveness of computer security controls built into a computer system?

The correct answer is B. TCSEC. TCSEC (Trusted Computer System Evaluation Criteria), commonly called the Orange Book, was published by the U.S. DoD's National Computer Security Center (NCSC). It defines criteria for evaluating and classifying the security effectiveness of computer systems, organizing systems…

Assessment/Audit of Security and Privacy Controls

Question

Which of the following is a standard that sets basic requirements for assessing the effectiveness of computer security controls built into a computer system?

Options

  • AFITSAF
  • BTCSEC
  • CFIPS
  • DSSAA

How the community answered

(29 responses)
  • B
    90% (26)
  • C
    7% (2)
  • D
    3% (1)

Explanation

TCSEC (Trusted Computer System Evaluation Criteria), commonly called the Orange Book, was published by the U.S. DoD's National Computer Security Center (NCSC). It defines criteria for evaluating and classifying the security effectiveness of computer systems, organizing systems into hierarchical divisions (D, C1, C2, B1, B2, B3, A1) based on security features and assurance. FITSAF is a framework for assessing federal IT security posture; FIPS are general processing standards; and SSAA is a DoD authorization document - none of these specifically evaluate built-in computer security controls the way TCSEC does.

Topics

#TCSEC#Security evaluation standards#Control assessment#System security

Community Discussion

No community discussion yet for this question.

Full CAP Practice