nerdexam
(ISC)2

CGRC · Question #410

Testing officials should use which NIST publication as guide for developing test procedures? Response:

The correct answer is A. NIST SP 800-53A. Testing officials should primarily use NIST SP 800-53A as a guide for developing test procedures because it provides detailed assessment procedures and methods for evaluating the effectiveness of security controls. This publication offers specific guidance on how to assess…

Assessment/Audit of Security and Privacy Controls

Question

Testing officials should use which NIST publication as guide for developing test procedures? Response:

Options

  • ANIST SP 800-53A
  • BNIST SP 800-37A
  • CNIST SP 800-39
  • DNIST SP 800-53

How the community answered

(64 responses)
  • A
    92% (59)
  • B
    2% (1)
  • C
    5% (3)
  • D
    2% (1)

Why each option

Testing officials should primarily use NIST SP 800-53A as a guide for developing test procedures because it provides detailed assessment procedures and methods for evaluating the effectiveness of security controls. This publication offers specific guidance on how to assess whether controls are implemented correctly and operating as intended.

ANIST SP 800-53ACorrect

NIST SP 800-53A, "Assessing Security and Privacy Controls in Federal Information Systems and Organizations," is the definitive NIST guide for developing test procedures and assessing security controls. It outlines the specific assessment methods, including examine, interview, and test, for each control and control enhancement.

BNIST SP 800-37A

NIST SP 800-37A does not exist. NIST SP 800-37 is the "Guide for Applying the Risk Management Framework," which is a process, not a guide for developing test procedures.

CNIST SP 800-39

NIST SP 800-39, "Managing Information Security Risk," provides an organizational-level approach to risk management, not detailed guidance for developing technical test procedures.

DNIST SP 800-53

NIST SP 800-53, "Security and Privacy Controls for Federal Information Systems and Organizations," defines the security controls themselves, but not the procedures for testing them; that is the purpose of 800-53A.

Concept tested: NIST SP 800-53A for test procedures

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf

Topics

#NIST SP 800-53A#Control Assessment#Test Procedures

Community Discussion

No community discussion yet for this question.

Full CGRC Practice