CGRC · Question #548
Organizations implement safeguards and countermeasures to protect information resources from risks. One of the following is an administrative safeguard family implemented by the management of an organ
The correct answer is A. Certification and accreditation. Certification and accreditation (C&A) is an administrative safeguard family, as it represents a management-driven process for formally authorizing systems to operate based on their security posture. It establishes management accountability and oversight.
Question
Organizations implement safeguards and countermeasures to protect information resources from risks. One of the following is an administrative safeguard family implemented by the management of an organization. Response:
Options
- ACertification and accreditation
- BEcryption and integrity checks
- CFIPS 199 and NIST SP 800-37
- DImplementation and Assessment
How the community answered
(31 responses)- A90% (28)
- B3% (1)
- D6% (2)
Why each option
Certification and accreditation (C&A) is an administrative safeguard family, as it represents a management-driven process for formally authorizing systems to operate based on their security posture. It establishes management accountability and oversight.
Certification and accreditation (C&A), now generally referred to as the Authorization step in the NIST Risk Management Framework (RMF), is an administrative safeguard family because it is a formal management decision process. It involves management review, approval, and acceptance of residual risk for an information system to operate within an organizational environment. This process establishes accountability, ensures adherence to policies, and leverages management's authority to make informed decisions about system security and operational authorization, making it a critical administrative control.
Encryption and integrity checks are technical safeguards that use algorithms and software to protect data, not administrative processes.
FIPS 199 and NIST SP 800-37 are standards and frameworks, respectively, not safeguard families themselves.
Implementation and Assessment are phases or activities within the security lifecycle, not a family of administrative safeguards.
Concept tested: Administrative safeguard families
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.