nerdexam
(ISC)2

CGRC · Question #548

Organizations implement safeguards and countermeasures to protect information resources from risks. One of the following is an administrative safeguard family implemented by the management of an organ

The correct answer is A. Certification and accreditation. Certification and accreditation (C&A) is an administrative safeguard family, as it represents a management-driven process for formally authorizing systems to operate based on their security posture. It establishes management accountability and oversight.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Organizations implement safeguards and countermeasures to protect information resources from risks. One of the following is an administrative safeguard family implemented by the management of an organization. Response:

Options

  • ACertification and accreditation
  • BEcryption and integrity checks
  • CFIPS 199 and NIST SP 800-37
  • DImplementation and Assessment

How the community answered

(31 responses)
  • A
    90% (28)
  • B
    3% (1)
  • D
    6% (2)

Why each option

Certification and accreditation (C&A) is an administrative safeguard family, as it represents a management-driven process for formally authorizing systems to operate based on their security posture. It establishes management accountability and oversight.

ACertification and accreditationCorrect

Certification and accreditation (C&A), now generally referred to as the Authorization step in the NIST Risk Management Framework (RMF), is an administrative safeguard family because it is a formal management decision process. It involves management review, approval, and acceptance of residual risk for an information system to operate within an organizational environment. This process establishes accountability, ensures adherence to policies, and leverages management's authority to make informed decisions about system security and operational authorization, making it a critical administrative control.

BEcryption and integrity checks

Encryption and integrity checks are technical safeguards that use algorithms and software to protect data, not administrative processes.

CFIPS 199 and NIST SP 800-37

FIPS 199 and NIST SP 800-37 are standards and frameworks, respectively, not safeguard families themselves.

DImplementation and Assessment

Implementation and Assessment are phases or activities within the security lifecycle, not a family of administrative safeguards.

Concept tested: Administrative safeguard families

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Administrative safeguards#Certification and Accreditation#Security controls#NIST RMF

Community Discussion

No community discussion yet for this question.

Full CGRC Practice