nerdexam
(ISC)2

CGRC · Question #68

Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management is the title of what requirement? Response:

The correct answer is A. OMB memorandum M-11-33, FY 2011. OMB Memorandum M-11-33 (FY 2011) is specifically titled "Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management."

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management is the title of what requirement? Response:

Options

  • AOMB memorandum M-11-33, FY 2011
  • BClinger-Cohen Act
  • COMB Circular A-130, Appendix III, 1997
  • DFISMA, 2002

How the community answered

(21 responses)
  • A
    95% (20)
  • C
    5% (1)

Why each option

OMB Memorandum M-11-33 (FY 2011) is specifically titled "Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management."

AOMB memorandum M-11-33, FY 2011Correct

OMB Memorandum M-11-33, issued in Fiscal Year 2011, provided specific, detailed instructions to federal agencies on their reporting requirements under the Federal Information Security Management Act (FISMA) and for agency privacy management. This memorandum outlined the metrics and procedures agencies needed to follow for their annual security reporting.

BClinger-Cohen Act

The Clinger-Cohen Act (1996) is a broader legislation focused on IT management and investment, not specifically "Reporting Instructions for FISMA and Privacy Management."

COMB Circular A-130, Appendix III, 1997

OMB Circular A-130, Appendix III (1997), titled "Security of Federal Automated Information Resources," was a foundational document for federal information security but predates the specific M-11-33 reporting instructions.

DFISMA, 2002

FISMA (Federal Information Security Management Act) of 2002 is the law that mandates federal agencies to develop, document, and implement information security programs, but it is not the "Reporting Instructions" document itself.

Concept tested: Federal information security reporting requirements

Source: https://www.whitehouse.gov/wp-content/uploads/2017/11/m-11-33.pdf

Topics

#OMB M-11-33#FISMA reporting#Privacy management#Federal directives

Community Discussion

No community discussion yet for this question.

Full CGRC Practice