nerdexam
(ISC)2

CGRC · Question #702

Which of the following acts promote a risk-based policy for cost effective security? Each correct answer represents a part of the solution. Choose all that apply. Response:

The correct answer is A. Clinger-Cohen Act D. Paperwork Reduction Act (PRA). This question asks which U.S. federal acts promote a risk-based approach to cost-effective information security. Both the Clinger-Cohen Act and the Paperwork Reduction Act are relevant in this context.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following acts promote a risk-based policy for cost effective security? Each correct answer represents a part of the solution. Choose all that apply. Response:

Options

  • AClinger-Cohen Act
  • BLanham Act
  • CComputer Misuse Act
  • DPaperwork Reduction Act (PRA)

How the community answered

(38 responses)
  • A
    89% (34)
  • B
    8% (3)
  • C
    3% (1)

Why each option

This question asks which U.S. federal acts promote a risk-based approach to cost-effective information security. Both the Clinger-Cohen Act and the Paperwork Reduction Act are relevant in this context.

AClinger-Cohen ActCorrect

The Clinger-Cohen Act mandates federal agencies to use a capital planning and investment control process for IT investments, which includes managing risks and ensuring cost-effectiveness in security. It requires agencies to explicitly consider the return on investment and risk in their IT spending.

BLanham Act

The Lanham Act primarily governs trademarks, service marks, and unfair competition in the United States, and does not directly address risk-based IT security policies.

CComputer Misuse Act

The Computer Misuse Act is a United Kingdom law that addresses computer hacking and unauthorized access, not a U.S. federal act promoting risk-based cost-effective security policies.

DPaperwork Reduction Act (PRA)Correct

The Paperwork Reduction Act (PRA) requires federal agencies to manage information resources efficiently and effectively, including establishing security policies and practices based on a risk-based approach to protect information assets.

Concept tested: Federal acts for risk-based IT security

Source: https://www.gsa.gov/governmentwide-initiatives/federal-acquisition-regulation-far/it-regulations-policies/clinger-cohen-act

Topics

#US Federal Acts#IT Governance#Risk-based security#Cost-effective security

Community Discussion

No community discussion yet for this question.

Full CGRC Practice