CGRC · Question #647
The scope of certification normally addresses all NIST SP _________ control families with the purpose of uncovering design, implementation, and operational flows in those controls. Response:
The correct answer is A. NIST SP 800-53. The scope of certification and assessment activities typically focuses on the security control families outlined in NIST SP 800-53, which provides a comprehensive catalog of controls for federal information systems. The aim is to identify any flaws in their design…
Question
The scope of certification normally addresses all NIST SP _________ control families with the purpose of uncovering design, implementation, and operational flows in those controls. Response:
Options
- ANIST SP 800-53
- BNIST SP 800-37
- CNIST SP 800-53A
- DNIST SP 800-39
How the community answered
(52 responses)- A88% (46)
- B4% (2)
- C6% (3)
- D2% (1)
Why each option
The scope of certification and assessment activities typically focuses on the security control families outlined in NIST SP 800-53, which provides a comprehensive catalog of controls for federal information systems. The aim is to identify any flaws in their design, implementation, and operation.
NIST SP 800-53, "Security and Privacy Controls for Information Systems and Organizations," defines the catalog of control families that are assessed during certification activities to ensure comprehensive coverage of security requirements.
NIST SP 800-37, "Risk Management Framework for Information Systems and Organizations," describes the RMF process, not the catalog of controls itself.
NIST SP 800-53A, "Assessing Security and Privacy Controls in Federal Information Systems and Organizations," provides assessment procedures for the controls listed in 800-53, but 800-53 itself contains the control families.
NIST SP 800-39, "Managing Information Security Risk: Organization, Mission, and System View," focuses on enterprise-wide risk management, not the specific control families.
Concept tested: NIST security control catalog
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.