nerdexam
(ISC)2

CGRC · Question #15

The FISMA defines three security objectives for information and information systems: Response:

The correct answer is A. CONFIDENTIALITY, INTEGRITY and AVAILABILITY. The Federal Information Security Modernization Act (FISMA) mandates that all federal agencies protect information and information systems based on the three core security objectives: Confidentiality, Integrity, and Availability (CIA triad).

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The FISMA defines three security objectives for information and information systems:

Response:

Options

  • ACONFIDENTIALITY, INTEGRITY and AVAILABILITY
  • BINTEGRITY, AVAILABILITY and AUTHENTICITY
  • CAVAILABILITY, AUTHENTICITY and CONFIDENTIALITY
  • DAUTHENTICITY, CONFIDENTIALITY and INTEGRITY

How the community answered

(35 responses)
  • A
    89% (31)
  • B
    3% (1)
  • C
    3% (1)
  • D
    6% (2)

Why each option

The Federal Information Security Modernization Act (FISMA) mandates that all federal agencies protect information and information systems based on the three core security objectives: Confidentiality, Integrity, and Availability (CIA triad).

ACONFIDENTIALITY, INTEGRITY and AVAILABILITYCorrect

FISMA explicitly identifies Confidentiality, Integrity, and Availability (the CIA triad) as the fundamental security objectives for all information and information systems under its purview. These three principles form the bedrock of information security programs and risk assessments for federal agencies.

BINTEGRITY, AVAILABILITY and AUTHENTICITY

Authenticity is a security property but not one of the three core objectives explicitly defined by FISMA alongside Integrity and Availability.

CAVAILABILITY, AUTHENTICITY and CONFIDENTIALITY

Authenticity is a security property but not one of the three core objectives explicitly defined by FISMA alongside Availability and Confidentiality.

DAUTHENTICITY, CONFIDENTIALITY and INTEGRITY

Authenticity is a security property but not one of the three core objectives explicitly defined by FISMA alongside Confidentiality and Integrity.

Concept tested: FISMA Security Objectives (CIA Triad)

Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf

Topics

#FISMA#Security Objectives#CIA Triad#Information Security

Community Discussion

No community discussion yet for this question.

Full CGRC Practice