CGRC · Question #180
For which of the following reporting requirements are continuous monitoring documentation reports used? Response:
The correct answer is A. FISMA. Continuous monitoring documentation reports are crucial for federal agencies to satisfy the mandatory reporting requirements established by the Federal Information Security Modernization Act (FISMA).
Question
For which of the following reporting requirements are continuous monitoring documentation reports used? Response:
Options
- AFISMA
- BNIST
- CHIPAA
- DFBI
How the community answered
(19 responses)- A95% (18)
- C5% (1)
Why each option
Continuous monitoring documentation reports are crucial for federal agencies to satisfy the mandatory reporting requirements established by the Federal Information Security Modernization Act (FISMA).
FISMA mandates that federal agencies implement and report on their information security programs, with continuous monitoring being a key component. Documentation reports generated from continuous monitoring efforts provide the necessary evidence and data to demonstrate ongoing compliance with FISMA's stringent security and reporting requirements.
NIST develops the *guidelines and frameworks* for continuous monitoring, but it is FISMA that *mandates* the reporting for federal systems.
HIPAA governs the privacy and security of health information, requiring compliance reports, but it does not broadly mandate continuous monitoring documentation reports for federal information systems in the same way as FISMA.
The FBI is a law enforcement agency and does not issue general continuous monitoring reporting requirements for all federal information systems.
Concept tested: FISMA continuous monitoring reporting
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-137.pdf
Topics
Community Discussion
No community discussion yet for this question.