nerdexam
(ISC)2

CGRC · Question #106

Which of the following created FISMA requirements, requiring System Authorization? Response:

The correct answer is D. An Act of Congress. The Federal Information Security Modernization Act (FISMA) requirements, including system authorization, were established through an Act of Congress.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following created FISMA requirements, requiring System Authorization? Response:

Options

  • ADISA
  • BWhite House
  • CDepartment of Defense
  • DAn Act of Congress

How the community answered

(59 responses)
  • A
    7% (4)
  • B
    3% (2)
  • C
    2% (1)
  • D
    88% (52)

Why each option

The Federal Information Security Modernization Act (FISMA) requirements, including system authorization, were established through an Act of Congress.

ADISA

DISA (Defense Information Systems Agency) is a Department of Defense agency that provides IT and communications support, but it did not create FISMA.

BWhite House

The White House issues executive orders and directives, but legislative acts like FISMA are passed by Congress.

CDepartment of Defense

The Department of Defense is a federal agency subject to FISMA, but it did not create the act itself.

DAn Act of CongressCorrect

The Federal Information Security Management Act (FISMA), which mandates requirements for federal agencies to secure their information and information systems, including the process of system authorization, was enacted into law as an Act of Congress in 2002 and updated in 2014.

Concept tested: Origins of FISMA.

Source: https://csrc.nist.gov/glossary/term/federal-information-security-modernization-act-fisma

Topics

#FISMA#Legislation#System Authorization

Community Discussion

No community discussion yet for this question.

Full CGRC Practice