CISSP-ISSEP · Question #66
Which of the following organizations is a USG initiative designed to meet the security testing, evaluation, and assessment needs of both information technology (IT) producers and consumers?
The correct answer is D. NIAP. NIAP (National Information Assurance Partnership) is specifically a USG initiative - originally a partnership between NSA and NIST - created to administer the Common Criteria Evaluation and Validation Scheme (CCEVS), which exists precisely to evaluate and validate IT security…
Question
Which of the following organizations is a USG initiative designed to meet the security testing, evaluation, and assessment needs of both information technology (IT) producers and consumers?
Options
- ANSA
- BNIST
- CCNSS
- DNIAP
How the community answered
(61 responses)- A3% (2)
- C2% (1)
- D95% (58)
Explanation
NIAP (National Information Assurance Partnership) is specifically a USG initiative - originally a partnership between NSA and NIST - created to administer the Common Criteria Evaluation and Validation Scheme (CCEVS), which exists precisely to evaluate and validate IT security products for both the vendors who build them (producers) and the agencies/organizations that buy them (consumers). The NSA (A) is an intelligence and cybersecurity agency, not a product evaluation program. NIST (B) develops standards and guidelines (like FIPS and SP 800-series) but is not itself a testing/evaluation initiative for products. CNSS (C) sets policy for national security systems rather than performing product security assessments.
Memory tip: Think NIAP = "Need It Assessed? Partnership" - it's the go-to USG body when an IT product needs a formal security evaluation before procurement or sale.
Topics
Community Discussion
No community discussion yet for this question.