nerdexam
(ISC)2

CGRC · Question #64

Which of the following is a standard that sets basic requirements for assessing the effectiveness of computer security controls built into a computer system? Response:

The correct answer is B. TCSEC. The Trusted Computer System Evaluation Criteria (TCSEC), often called the "Orange Book," is a standard that historically set requirements for evaluating the effectiveness of computer security controls.

Assessment/Audit of Security and Privacy Controls

Question

Which of the following is a standard that sets basic requirements for assessing the effectiveness of computer security controls built into a computer system? Response:

Options

  • AFITSAF
  • BTCSEC
  • CFIPS
  • DSSAA

How the community answered

(19 responses)
  • B
    89% (17)
  • C
    5% (1)
  • D
    5% (1)

Why each option

The Trusted Computer System Evaluation Criteria (TCSEC), often called the "Orange Book," is a standard that historically set requirements for evaluating the effectiveness of computer security controls.

AFITSAF

FITSAF (Federal Information Technology Security Assessment Framework) is not a widely recognized standard for assessing the effectiveness of computer security controls.

BTCSECCorrect

The Trusted Computer System Evaluation Criteria (TCSEC), also known as the "Orange Book," was a U.S. government standard that defined different classes of security and provided a framework for evaluating the effectiveness of computer security controls. It detailed requirements for trusted systems based on confidentiality.

CFIPS

FIPS (Federal Information Processing Standards) are a set of standards issued by NIST, but FIPS itself is an umbrella for many standards, not a single standard for assessing overall computer system security control effectiveness like TCSEC.

DSSAA

SSAA (System Security Accreditation Agreement) is part of a certification and accreditation process, not a standard defining requirements for assessing control effectiveness.

Concept tested: Historical computer security evaluation standards

Source: https://csrc.nist.gov/publications/detail/dod/5200.28-std/archive/1985/archive

Topics

#TCSEC#Security Control Assessment#Computer System Evaluation#Historical Security Standards

Community Discussion

No community discussion yet for this question.

Full CGRC Practice