nerdexam
(ISC)2

CGRC · Question #56

Security categorization of an National Security System must consider the security categories of all information types resident on it. Response:

The correct answer is A. True. For National Security Systems, it is true that the security categories of all resident information types must be considered during categorization. This ensures that the system's overall security posture adequately protects the most sensitive information it handles.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Security categorization of an National Security System must consider the security categories of all information types resident on it. Response:

Options

  • ATrue
  • BFalse

How the community answered

(53 responses)
  • A
    92% (49)
  • B
    8% (4)

Why each option

For National Security Systems, it is true that the security categories of all resident information types must be considered during categorization. This ensures that the system's overall security posture adequately protects the most sensitive information it handles.

ATrueCorrect

True. When determining the security categorization for a National Security System (NSS), it is a requirement to consider the security categories (Confidentiality, Integrity, Availability) of every type of information processed, stored, or transmitted by that system to establish its overall security impact level.

BFalse

Concept tested: National Security System security categorization

Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf

Topics

#Security Categorization#National Security System#Information Types#Risk Management Framework

Community Discussion

No community discussion yet for this question.

Full CGRC Practice