CSSLP · Question #150
Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct answ
The correct answer is B. Office of Management and Budget (OMB) D. FISMA. The Federal Information Security Modernization Act (FISMA) mandates that federal agencies certify and accredit their general support systems and major applications, with the Office of Management and Budget (OMB) providing guidance and oversight for this process.
Question
Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct answer represents a part of the solution. Choose all that apply.
Options
- ANIST
- BOffice of Management and Budget (OMB)
- CFIPS
- DFISMA
How the community answered
(29 responses)- A3% (1)
- B93% (27)
- C3% (1)
Why each option
The Federal Information Security Modernization Act (FISMA) mandates that federal agencies certify and accredit their general support systems and major applications, with the Office of Management and Budget (OMB) providing guidance and oversight for this process.
NIST (National Institute of Standards and Technology) develops the standards and guidelines (like the 800-series publications) that agencies use to comply with FISMA and OMB directives, but it does not require certification and accreditation itself.
The Office of Management and Budget (OMB) circulars, particularly OMB Circular A-130, provide policy guidance to federal agencies regarding the implementation of FISMA, including requirements for security authorization (certification and accreditation).
FIPS (Federal Information Processing Standards) are specific standards published by NIST for federal computer systems, but they are the standards to follow, not the overarching requirement for certification and accreditation.
The Federal Information Security Modernization Act (FISMA) of 2014, and its predecessor FISMA of 2002, legally mandates that federal agencies develop, document, and implement an agency-wide information security program, including the certification and accreditation (now called authorization) of all major applications and general support systems before they are put into production.
Concept tested: FISMA and OMB A-130 certification/accreditation
Source: https://www.whitehouse.gov/omb/information-for-agencies/circulars/
Topics
Community Discussion
No community discussion yet for this question.