nerdexam
(ISC)2

CGRC · Question #552

According to FISMA and OMB policy, external subsystems are required to meet the same security requirements as systems operated internally.................... Response:

The correct answer is A. by government organizations. FISMA and OMB policies stipulate that external subsystems providing services to the government must adhere to the same security requirements as systems operated internally by government organizations.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

According to FISMA and OMB policy, external subsystems are required to meet the same security requirements as systems operated internally.................... Response:

Options

  • Aby government organizations
  • Bby private organizations
  • Cby government unorganizations
  • Dby government unapproved organizations

How the community answered

(54 responses)
  • A
    87% (47)
  • B
    2% (1)
  • C
    4% (2)
  • D
    7% (4)

Why each option

FISMA and OMB policies stipulate that external subsystems providing services to the government must adhere to the same security requirements as systems operated internally by government organizations.

Aby government organizationsCorrect

FISMA (Federal Information Security Modernization Act) and OMB (Office of Management and Budget) policies extend security requirements to external entities supporting government operations to ensure consistent protection of federal information and systems. This mandate ensures that the security posture of federal information remains robust regardless of whether the system is operated directly by a government organization or a third party.

Bby private organizations

Private organizations are generally not subject to FISMA and OMB policy unless they are contracted to provide services to a government entity, which then brings them under government security mandates.

Cby government unorganizations

"Government unorganizations" is not a recognized term in federal policy or security frameworks.

Dby government unapproved organizations

"Government unapproved organizations" is not a standard term used in FISMA or OMB policies to describe entities subject to their security requirements.

Concept tested: FISMA and OMB external system security requirements

Source: https://www.nist.gov/privacy-framework/federal-information-security-modernization-act-fisma-and-associated-documents

Topics

#FISMA#OMB policy#Government security requirements#External systems

Community Discussion

No community discussion yet for this question.

Full CGRC Practice