nerdexam
(ISC)2

CGRC · Question #454

The guidelines in this publication apply to the security controls defined in NIST Special Publication 800 53 in an effort to enable more consistent, comparable, and repeatable assessments of…

The correct answer is B. SP 800 53A. The question describes a NIST publication that provides guidelines for assessing security controls, specifically those defined in SP 800-53, to ensure consistent and repeatable evaluations.

Assessment/Audit of Security and Privacy Controls

Question

The guidelines in this publication apply to the security controls defined in NIST Special Publication 800 53 in an effort to enable more consistent, comparable, and repeatable assessments of security controls. Response:

Options

  • ASP 800 53
  • BSP 800 53A
  • CSP 800 37
  • DFIPS 200

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    86% (24)
  • C
    4% (1)
  • D
    7% (2)

Why each option

The question describes a NIST publication that provides guidelines for assessing security controls, specifically those defined in SP 800-53, to ensure consistent and repeatable evaluations.

ASP 800 53

NIST SP 800-53 defines the security controls themselves, not the guidelines for assessing them.

BSP 800 53ACorrect

NIST Special Publication 800-53A, "Assessing Security and Privacy Controls in Information Systems and Organizations," provides a comprehensive methodology for conducting assessments of security controls. It details assessment procedures and methods to determine the effectiveness of security controls defined in NIST SP 800-53, ensuring consistency, comparability, and repeatability across assessments.

CSP 800 37

NIST SP 800-37 describes the Risk Management Framework (RMF), which is the overarching process for managing security and privacy risk, but it does not detail the specific assessment procedures for individual controls.

DFIPS 200

FIPS 200, "Minimum Security Requirements for Federal Information and Information Systems," sets the minimum security requirements, referencing SP 800-53 for controls, but does not provide assessment guidelines.

Concept tested: NIST SP 800-53A Role

Source: https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final

Topics

#NIST SP 800-53A#Security Control Assessment#Assessment Guidelines#NIST Publications

Community Discussion

No community discussion yet for this question.

Full CGRC Practice