CGRC · Question #15
The FISMA defines three security objectives for information and information systems: Response:
The correct answer is A. CONFIDENTIALITY, INTEGRITY and AVAILABILITY. The Federal Information Security Modernization Act (FISMA) mandates that all federal agencies protect information and information systems based on the three core security objectives: Confidentiality, Integrity, and Availability (CIA triad).
Question
The FISMA defines three security objectives for information and information systems:
Response:
Options
- ACONFIDENTIALITY, INTEGRITY and AVAILABILITY
- BINTEGRITY, AVAILABILITY and AUTHENTICITY
- CAVAILABILITY, AUTHENTICITY and CONFIDENTIALITY
- DAUTHENTICITY, CONFIDENTIALITY and INTEGRITY
How the community answered
(35 responses)- A89% (31)
- B3% (1)
- C3% (1)
- D6% (2)
Why each option
The Federal Information Security Modernization Act (FISMA) mandates that all federal agencies protect information and information systems based on the three core security objectives: Confidentiality, Integrity, and Availability (CIA triad).
FISMA explicitly identifies Confidentiality, Integrity, and Availability (the CIA triad) as the fundamental security objectives for all information and information systems under its purview. These three principles form the bedrock of information security programs and risk assessments for federal agencies.
Authenticity is a security property but not one of the three core objectives explicitly defined by FISMA alongside Integrity and Availability.
Authenticity is a security property but not one of the three core objectives explicitly defined by FISMA alongside Availability and Confidentiality.
Authenticity is a security property but not one of the three core objectives explicitly defined by FISMA alongside Confidentiality and Integrity.
Concept tested: FISMA Security Objectives (CIA Triad)
Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf
Topics
Community Discussion
No community discussion yet for this question.