nerdexam
(ISC)2

CISSP-ISSEP · Question #66

Which of the following organizations is a USG initiative designed to meet the security testing, evaluation, and assessment needs of both information technology (IT) producers and consumers?

The correct answer is D. NIAP. NIAP (National Information Assurance Partnership) is specifically a USG initiative - originally a partnership between NSA and NIST - created to administer the Common Criteria Evaluation and Validation Scheme (CCEVS), which exists precisely to evaluate and validate IT security…

Supply Chain Security

Question

Which of the following organizations is a USG initiative designed to meet the security testing, evaluation, and assessment needs of both information technology (IT) producers and consumers?

Options

  • ANSA
  • BNIST
  • CCNSS
  • DNIAP

How the community answered

(61 responses)
  • A
    3% (2)
  • C
    2% (1)
  • D
    95% (58)

Explanation

NIAP (National Information Assurance Partnership) is specifically a USG initiative - originally a partnership between NSA and NIST - created to administer the Common Criteria Evaluation and Validation Scheme (CCEVS), which exists precisely to evaluate and validate IT security products for both the vendors who build them (producers) and the agencies/organizations that buy them (consumers). The NSA (A) is an intelligence and cybersecurity agency, not a product evaluation program. NIST (B) develops standards and guidelines (like FIPS and SP 800-series) but is not itself a testing/evaluation initiative for products. CNSS (C) sets policy for national security systems rather than performing product security assessments.

Memory tip: Think NIAP = "Need It Assessed? Partnership" - it's the go-to USG body when an IT product needs a formal security evaluation before procurement or sale.

Topics

#NIAP#IT Security Testing#Common Criteria#Government Initiatives

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSEP Practice