CGRC · Question #456
Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct…
The correct answer is C. FISMA D. Office of Management and Budget (OMB). The question asks which entities or regulations mandate that federal general support systems and major applications undergo full certification and accreditation prior to production deployment.
Question
Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct answer represents a part of the solution. Choose all that apply. Response:
Options
- ANIST
- BFIPS
- CFISMA
- DOffice of Management and Budget (OMB)
How the community answered
(29 responses)- A3% (1)
- B3% (1)
- C93% (27)
Why each option
The question asks which entities or regulations mandate that federal general support systems and major applications undergo full certification and accreditation prior to production deployment.
NIST (National Institute of Standards and Technology) develops standards and guidelines for federal information systems but does not issue legal mandates for C&A itself.
FIPS (Federal Information Processing Standards) are publications by NIST that specify requirements for federal information systems, such as encryption standards, but they are not the legal mandate for C&A.
The Federal Information Security Modernization Act (FISMA) of 2014, and its predecessor FISMA 2002, legally mandates that federal agencies develop, document, and implement agency-wide information security programs, including the certification and accreditation (now authorization) of information systems.
The Office of Management and Budget (OMB), through various circulars (e.g., OMB Circular A-130, Appendix III), provides policy guidance and directives to federal agencies for implementing FISMA, explicitly requiring the certification and accreditation (C&A) or authorization of federal information systems before operation.
Concept tested: FISMA and OMB C&A Requirements
Source: https://www.cisa.gov/federal-information-security-modernization-act-fisma
Topics
Community Discussion
No community discussion yet for this question.