nerdexam
(ISC)2

CGRC · Question #61

An application that requires special attention to security due to the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the ap

The correct answer is A. Major Application. This definition describes a "Major Application" in the context of federal information security, emphasizing heightened security scrutiny due to potential harm from compromise.

Scope of the System

Question

An application that requires special attention to security due to the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the application. Note: All federal applications require some level of protection. Certain applications, because of the information in them, however, require special management oversight and should be treated as major. Adequate security for other applications should be provided by security of the systems in which they operate. Response:

Options

  • AMajor Application
  • BHumble Application
  • CSlight Application
  • DWorthless Application

How the community answered

(60 responses)
  • A
    93% (56)
  • B
    2% (1)
  • D
    5% (3)

Why each option

This definition describes a "Major Application" in the context of federal information security, emphasizing heightened security scrutiny due to potential harm from compromise.

AMajor ApplicationCorrect

Major Application is the specific term used in federal information security guidelines (e.g., FIPS Publication 199 or OMB Circular A-130, Appendix III) to categorize applications requiring special management attention and rigorous security controls due to the high risk and magnitude of harm associated with data breaches. These applications typically process sensitive information, necessitating a more robust security posture than less critical applications.

BHumble Application

"Humble Application" is not a recognized term in IT security categorization.

CSlight Application

"Slight Application" is not a recognized term in IT security categorization.

DWorthless Application

"Worthless Application" is not a recognized term in IT security categorization and contradicts the premise of requiring special security attention.

Concept tested: Federal information system categorization, Major Application

Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf

Topics

#Major Application#Information System Categorization#Federal Information Systems#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full CGRC Practice