nerdexam
(ISC)2

CGRC · Question #456

Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct…

The correct answer is C. FISMA D. Office of Management and Budget (OMB). The question asks which entities or regulations mandate that federal general support systems and major applications undergo full certification and accreditation prior to production deployment.

System Compliance

Question

Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct answer represents a part of the solution. Choose all that apply. Response:

Options

  • ANIST
  • BFIPS
  • CFISMA
  • DOffice of Management and Budget (OMB)

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    93% (27)

Why each option

The question asks which entities or regulations mandate that federal general support systems and major applications undergo full certification and accreditation prior to production deployment.

ANIST

NIST (National Institute of Standards and Technology) develops standards and guidelines for federal information systems but does not issue legal mandates for C&A itself.

BFIPS

FIPS (Federal Information Processing Standards) are publications by NIST that specify requirements for federal information systems, such as encryption standards, but they are not the legal mandate for C&A.

CFISMACorrect

The Federal Information Security Modernization Act (FISMA) of 2014, and its predecessor FISMA 2002, legally mandates that federal agencies develop, document, and implement agency-wide information security programs, including the certification and accreditation (now authorization) of information systems.

DOffice of Management and Budget (OMB)Correct

The Office of Management and Budget (OMB), through various circulars (e.g., OMB Circular A-130, Appendix III), provides policy guidance and directives to federal agencies for implementing FISMA, explicitly requiring the certification and accreditation (C&A) or authorization of federal information systems before operation.

Concept tested: FISMA and OMB C&A Requirements

Source: https://www.cisa.gov/federal-information-security-modernization-act-fisma

Topics

#Federal Compliance#Security Authorization#FISMA#OMB Policy

Community Discussion

No community discussion yet for this question.

Full CGRC Practice