nerdexam
(ISC)2

CGRC · Question #32

Defining the types of information needed by the organization to successfully carry out identified missions and business processes as well as defining the organization's internal and external…

The correct answer is A. NIST SP 800-60. The question describes the process of identifying and categorizing organizational information, which is the primary focus of NIST Special Publication 800-60. This publication provides guidelines for categorizing information systems based on their impact.

Scope of the System

Question

Defining the types of information needed by the organization to successfully carry out identified missions and business processes as well as defining the organization's internal and external information flows. Response:

Options

  • ANIST SP 800-60
  • BNIST SP 800-57
  • CNIST SP 800-50
  • DNIST SP 800-37

How the community answered

(47 responses)
  • A
    87% (41)
  • B
    9% (4)
  • C
    4% (2)

Why each option

The question describes the process of identifying and categorizing organizational information, which is the primary focus of NIST Special Publication 800-60. This publication provides guidelines for categorizing information systems based on their impact.

ANIST SP 800-60Correct

NIST SP 800-60, "Guide for Mapping Types of Information and Information Systems to Security Categories," provides guidance for organizations to identify and categorize their information and information systems, including defining information types and flows relevant to missions and business processes. This is crucial for applying appropriate security controls.

BNIST SP 800-57

NIST SP 800-57 focuses on cryptographic key management, not the classification of information types or flows.

CNIST SP 800-50

NIST SP 800-50 focuses on building an information technology security awareness and training program, which is different from defining information types.

DNIST SP 800-37

NIST SP 800-37 outlines the Risk Management Framework (RMF) process, which covers steps like categorizing systems, selecting controls, and monitoring, but does not specifically define the types of information and flows as its primary objective.

Concept tested: NIST Special Publication 800-60 purpose

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v1r1.pdf

Topics

#NIST SP 800-60#Information Classification#Information Flow#Security Categorization

Community Discussion

No community discussion yet for this question.

Full CGRC Practice