nerdexam
(ISC)2

CSSLP · Question #150

Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct answ

The correct answer is B. Office of Management and Budget (OMB) D. FISMA. The Federal Information Security Modernization Act (FISMA) mandates that federal agencies certify and accredit their general support systems and major applications, with the Office of Management and Budget (OMB) providing guidance and oversight for this process.

Secure Software Deployment, Operations, Maintenance

Question

Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct answer represents a part of the solution. Choose all that apply.

Options

  • ANIST
  • BOffice of Management and Budget (OMB)
  • CFIPS
  • DFISMA

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    93% (27)
  • C
    3% (1)

Why each option

The Federal Information Security Modernization Act (FISMA) mandates that federal agencies certify and accredit their general support systems and major applications, with the Office of Management and Budget (OMB) providing guidance and oversight for this process.

ANIST

NIST (National Institute of Standards and Technology) develops the standards and guidelines (like the 800-series publications) that agencies use to comply with FISMA and OMB directives, but it does not require certification and accreditation itself.

BOffice of Management and Budget (OMB)Correct

The Office of Management and Budget (OMB) circulars, particularly OMB Circular A-130, provide policy guidance to federal agencies regarding the implementation of FISMA, including requirements for security authorization (certification and accreditation).

CFIPS

FIPS (Federal Information Processing Standards) are specific standards published by NIST for federal computer systems, but they are the standards to follow, not the overarching requirement for certification and accreditation.

DFISMACorrect

The Federal Information Security Modernization Act (FISMA) of 2014, and its predecessor FISMA of 2002, legally mandates that federal agencies develop, document, and implement an agency-wide information security program, including the certification and accreditation (now called authorization) of all major applications and general support systems before they are put into production.

Concept tested: FISMA and OMB A-130 certification/accreditation

Source: https://www.whitehouse.gov/omb/information-for-agencies/circulars/

Topics

#Certification and Accreditation (C&A)#FISMA#OMB#Federal Compliance

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice