nerdexam
(ISC)2

CGRC · Question #388

Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the…

The correct answer is A. SA System and Services Acquisition B. CA Certification, Accreditation, and Security Assessments C. IR Incident Response. NIST Special Publication 800-53 defines a catalog of security and privacy controls organized into families, which serve as U.S. Federal Government information security standards.

Selection and Approval of Framework, Security, and Privacy Controls

Question

Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the following are the U.S. Federal Government information security standards? Each correct answer represents a complete solution. Choose all that apply. Response:

Options

  • ASA System and Services Acquisition
  • BCA Certification, Accreditation, and Security Assessments
  • CIR Incident Response
  • DInformation systems acquisition, development, and maintenance

How the community answered

(51 responses)
  • A
    90% (46)
  • D
    10% (5)

Why each option

NIST Special Publication 800-53 defines a catalog of security and privacy controls organized into families, which serve as U.S. Federal Government information security standards.

ASA System and Services AcquisitionCorrect

SA System and Services Acquisition is a control family specified in NIST SP 800-53, which provides guidance for acquiring systems, components, and services securely.

BCA Certification, Accreditation, and Security AssessmentsCorrect

CA Certification, Accreditation, and Security Assessments is another control family in NIST SP 800-53, focusing on the processes of assessing and authorizing information systems.

CIR Incident ResponseCorrect

IR Incident Response is also a control family defined in NIST SP 800-53, outlining requirements and guidelines for an organization's incident response capability.

DInformation systems acquisition, development, and maintenance

Information systems acquisition, development, and maintenance describes a broader lifecycle phase for systems, not a specific, two-letter acronym control family name as established in NIST SP 800-53.

Concept tested: NIST 800-53 control families

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

Topics

#NIST SP 800-53#Federal Information Security Standards#Security Control Families#Compliance Frameworks

Community Discussion

No community discussion yet for this question.

Full CGRC Practice