nerdexam
(ISC)2

CGRC · Question #535

Which of the following documents were developed by NIST for conducting Certification & Accreditation (C&A)? Each correct answer represents a complete solution. Choose all that apply. Response:

The correct answer is A. NIST Special Publication 800-53A C. NIST Special Publication 800-59 D. NIST Special Publication 800-53 E. NIST Special Publication 800-37 F. NIST Special Publication 800-60. NIST has developed several Special Publications that provide comprehensive guidance and standards for conducting Certification and Accreditation (C&A), now known as the Risk Management Framework (RMF). These documents cover categorization, control selection, assessment, and…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following documents were developed by NIST for conducting Certification & Accreditation (C&A)? Each correct answer represents a complete solution. Choose all that apply. Response:

Options

  • ANIST Special Publication 800-53A
  • BNIST Special Publication 800-37A
  • CNIST Special Publication 800-59
  • DNIST Special Publication 800-53
  • ENIST Special Publication 800-37
  • FNIST Special Publication 800-60

How the community answered

(38 responses)
  • A
    89% (34)
  • B
    11% (4)

Why each option

NIST has developed several Special Publications that provide comprehensive guidance and standards for conducting Certification and Accreditation (C&A), now known as the Risk Management Framework (RMF). These documents cover categorization, control selection, assessment, and authorization of information systems.

ANIST Special Publication 800-53ACorrect

NIST SP 800-53A provides guidance for assessing security controls, which is a critical part of the C&A process.

BNIST Special Publication 800-37A

NIST Special Publication 800-37A is not a recognized or existing NIST publication related to C&A; the primary document is NIST SP 800-37.

CNIST Special Publication 800-59Correct

NIST SP 800-59 offers guidelines for identifying national security systems, which influences their categorization and subsequent C&A process.

DNIST Special Publication 800-53Correct

NIST SP 800-53 defines the recommended security and privacy controls for federal information systems, forming the core of control selection in C&A.

ENIST Special Publication 800-37Correct

NIST SP 800-37 is the foundational guide for the Risk Management Framework (RMF), which evolved from and replaced the traditional C&A process.

FNIST Special Publication 800-60Correct

NIST SP 800-60 provides guidance for mapping information types to security categories, a crucial step in the categorization phase of C&A.

Concept tested: NIST C&A/RMF supporting publications

Source: https://csrc.nist.gov/publications/sp

Topics

#NIST Special Publications#Risk Management Framework#Certification and Accreditation#NIST RMF Documents

Community Discussion

No community discussion yet for this question.

Full CGRC Practice