CGRC · Question #81
Failure to authorize an operational system to process demonstrates that management has not exercised due care in protecting the system in the event of a security incident. Which of the following Acts
The correct answer is C. FISMA, 2002. Failing to authorize an operational system implies a lack of due care in protecting the system against security incidents, which is a violation of the Federal Information Security Management Act (FISMA) of 2002.
Question
Failure to authorize an operational system to process demonstrates that management has not exercised due care in protecting the system in the event of a security incident. Which of the following Acts has been violated? Response:
Options
- AClinger-Cohen Act of 1996
- BComputer security Act of 1987
- CFISMA, 2002
- DFIPS 102
How the community answered
(42 responses)- A2% (1)
- B5% (2)
- C90% (38)
- D2% (1)
Why each option
Failing to authorize an operational system implies a lack of due care in protecting the system against security incidents, which is a violation of the Federal Information Security Management Act (FISMA) of 2002.
The Clinger-Cohen Act of 1996 focuses on IT investment management and acquisition, not directly on the authorization of operational systems for security purposes in case of an incident.
The Computer Security Act of 1987 predates FISMA and focused on establishing minimum security requirements and training for federal computer systems, but FISMA significantly expanded and clarified these responsibilities, making it the more direct violation for authorization failures.
FISMA 2002 mandates that federal agencies develop, document, and implement an agency-wide information security program to protect information and information systems, including the formal authorization of systems to operate (ATO). Failure to authorize a system demonstrates a lapse in meeting these mandated security program requirements, thus violating FISMA's provisions for due care and system protection.
FIPS 102 is a Federal Information Processing Standard that deals with guidelines for computer security certification and accreditation, but it is a standard, not an Act that can be violated in the same legal sense as FISMA.
Concept tested: Federal information security regulations compliance
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.