nerdexam
(ISC)2

CGRC · Question #694

Which law was superseded by FISMA? The law required that systems processing federal data be authorized to process by a management official, and failure to do so will constitutes a violation of a…

The correct answer is D. Clinger-Cohen Act of 1996. The Clinger-Cohen Act of 1996 was a significant piece of legislation that mandated agencies to improve the acquisition and management of information technology. It was later largely superseded by the Federal Information Security Management Act (FISMA) of 2002, which…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which law was superseded by FISMA? The law required that systems processing federal data be authorized to process by a management official, and failure to do so will constitutes a violation of a federal directive. Response:

Options

  • AFIPS 102, 1983
  • BComputer security Act of 1987
  • COMB Circular A-130
  • DClinger-Cohen Act of 1996

How the community answered

(58 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    2% (1)
  • D
    93% (54)

Why each option

The Clinger-Cohen Act of 1996 was a significant piece of legislation that mandated agencies to improve the acquisition and management of information technology. It was later largely superseded by the Federal Information Security Management Act (FISMA) of 2002, which specifically focused on information security.

AFIPS 102, 1983

FIPS 102 is a federal information processing standard, not a law, and it deals with guidelines for computer security certification and accreditation.

BComputer security Act of 1987

The Computer Security Act of 1987 was a precursor to broader IT security legislation but was not directly superseded by FISMA in the same way Clinger-Cohen's IT management provisions were.

COMB Circular A-130

OMB Circular A-130 is a policy document issued by the Office of Management and Budget, not a law, and it provides guidance on managing federal information resources.

DClinger-Cohen Act of 1996Correct

The Clinger-Cohen Act of 1996, originally known as the Information Technology Management Reform Act, required federal agencies to designate Chief Information Officers (CIOs) and established responsibilities for IT management, including authorization of systems. FISMA 2002 built upon this foundation, creating a more comprehensive and robust framework for managing information security risks in federal government systems and operations, effectively superseding many IT security provisions of Clinger-Cohen.

Concept tested: History of U.S. federal IT security laws

Source: https://www.nist.gov/itl/applied-cybersecurity/nist-risk-management-framework/fisma

Topics

#FISMA#Clinger-Cohen Act#Federal Cybersecurity Legislation#Governance Evolution

Community Discussion

No community discussion yet for this question.

Full CGRC Practice