CGRC · Question #535
Which of the following documents were developed by NIST for conducting Certification & Accreditation (C&A)? Each correct answer represents a complete solution. Choose all that apply. Response:
The correct answer is A. NIST Special Publication 800-53A C. NIST Special Publication 800-59 D. NIST Special Publication 800-53 E. NIST Special Publication 800-37 F. NIST Special Publication 800-60. NIST has developed several Special Publications that provide comprehensive guidance and standards for conducting Certification and Accreditation (C&A), now known as the Risk Management Framework (RMF). These documents cover categorization, control selection, assessment, and…
Question
Which of the following documents were developed by NIST for conducting Certification & Accreditation (C&A)? Each correct answer represents a complete solution. Choose all that apply. Response:
Options
- ANIST Special Publication 800-53A
- BNIST Special Publication 800-37A
- CNIST Special Publication 800-59
- DNIST Special Publication 800-53
- ENIST Special Publication 800-37
- FNIST Special Publication 800-60
How the community answered
(38 responses)- A89% (34)
- B11% (4)
Why each option
NIST has developed several Special Publications that provide comprehensive guidance and standards for conducting Certification and Accreditation (C&A), now known as the Risk Management Framework (RMF). These documents cover categorization, control selection, assessment, and authorization of information systems.
NIST SP 800-53A provides guidance for assessing security controls, which is a critical part of the C&A process.
NIST Special Publication 800-37A is not a recognized or existing NIST publication related to C&A; the primary document is NIST SP 800-37.
NIST SP 800-59 offers guidelines for identifying national security systems, which influences their categorization and subsequent C&A process.
NIST SP 800-53 defines the recommended security and privacy controls for federal information systems, forming the core of control selection in C&A.
NIST SP 800-37 is the foundational guide for the Risk Management Framework (RMF), which evolved from and replaced the traditional C&A process.
NIST SP 800-60 provides guidance for mapping information types to security categories, a crucial step in the categorization phase of C&A.
Concept tested: NIST C&A/RMF supporting publications
Source: https://csrc.nist.gov/publications/sp
Topics
Community Discussion
No community discussion yet for this question.