nerdexam
(ISC)2

CGRC · Question #406

Which of the following NIST Special Publication documents provides a guideline on questionnaires and checklists through which systems can be evaluated for compliance against specific control…

The correct answer is F. NIST SP 800-53A. NIST SP 800-53A provides guidelines for assessing the security controls and control enhancements specified in NIST SP 800-53, offering methodologies, questionnaires, and checklists to evaluate system compliance. It details the procedures and methods used to determine if…

Assessment/Audit of Security and Privacy Controls

Question

Which of the following NIST Special Publication documents provides a guideline on questionnaires and checklists through which systems can be evaluated for compliance against specific control objectives? Response:

Options

  • ANIST SP 800-26
  • BNIST SP 800-53
  • CNIST SP 800-59
  • DNIST SP 800-60
  • ENIST SP 800-37
  • FNIST SP 800-53A

How the community answered

(46 responses)
  • A
    4% (2)
  • D
    2% (1)
  • E
    2% (1)
  • F
    91% (42)

Why each option

NIST SP 800-53A provides guidelines for assessing the security controls and control enhancements specified in NIST SP 800-53, offering methodologies, questionnaires, and checklists to evaluate system compliance. It details the procedures and methods used to determine if controls are implemented correctly, operating as intended, and producing the desired security outcome.

ANIST SP 800-26

NIST SP 800-26 (Security Self-Assessment Guide for IT Systems) is an older publication related to self-assessment, but 800-53A is the more comprehensive and current guide for control assessment.

BNIST SP 800-53

NIST SP 800-53 (Security and Privacy Controls for Federal Information Systems and Organizations) defines the controls themselves, not the assessment procedures or questionnaires.

CNIST SP 800-59

NIST SP 800-59 (Guideline for Identifying an Information System as a National Security System) focuses on system categorization, not control assessment.

DNIST SP 800-60

NIST SP 800-60 (Guide for Mapping Types of Information and Information Systems to Security Categories) addresses information and system categorization, not control assessment.

ENIST SP 800-37

NIST SP 800-37 (Guide for Applying the Risk Management Framework to Federal Information Systems) outlines the RMF process, but 800-53A provides the specific assessment guidance for the controls within that framework.

FNIST SP 800-53ACorrect

NIST SP 800-53A, "Assessing Security and Privacy Controls in Federal Information Systems and Organizations," provides detailed assessment procedures, including questionnaires and checklists, for evaluating the effectiveness of security controls defined in NIST SP 800-53. It is specifically designed to guide the assessment of compliance against control objectives.

Concept tested: NIST SP 800-53A for control assessment

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf

Topics

#NIST Special Publications#Control Assessment#Compliance Evaluation#NIST SP 800-53A

Community Discussion

No community discussion yet for this question.

Full CGRC Practice