nerdexam
(ISC)2

CGRC · Question #295

Which of the following is a goal of Public Law? Response:

The correct answer is D. Complete, reliable, and trustworthy information for Authorizing Officials. Public Law, particularly FISMA (Federal Information Security Modernization Act), aims to provide complete, reliable, and trustworthy information to Authorizing Officials to support their risk-based decision-making.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following is a goal of Public Law? Response:

Options

  • AReduce cost of security controls
  • BCompartmentalization of security information to increase security within departments of the
  • CEnsure that Authorizing Officials do not have budgetary authority over the systems they provide
  • DComplete, reliable, and trustworthy information for Authorizing Officials

How the community answered

(50 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    90% (45)

Why each option

Public Law, particularly FISMA (Federal Information Security Modernization Act), aims to provide complete, reliable, and trustworthy information to Authorizing Officials to support their risk-based decision-making.

AReduce cost of security controls

Reducing the cost of security controls is often desirable but not the primary stated goal of public law regarding information security, which focuses on effectiveness and risk management.

BCompartmentalization of security information to increase security within departments of the

Compartmentalization is a security technique, but not an overarching goal of public law, which typically promotes information sharing where appropriate for risk management.

CEnsure that Authorizing Officials do not have budgetary authority over the systems they provide

Public law does not specifically dictate that Authorizing Officials should lack budgetary authority; rather, it focuses on their responsibility for risk acceptance.

DComplete, reliable, and trustworthy information for Authorizing OfficialsCorrect

Public Laws like FISMA aim to ensure federal agencies manage information security effectively, providing Authorizing Officials with necessary complete, reliable, and trustworthy information to make informed risk-based decisions about system operation and acceptance of residual risk.

Concept tested: Goals of federal information security laws (e.g., FISMA)

Source: https://www.nist.gov/privacy-framework/federal-information-security-modernization-act-2014-fisma

Topics

#Public Law#Authorizing Officials (AO)#Information Quality#Governance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice