CSSLP · Question #232
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that…
The correct answer is A. Level 4. In the Federal Information Technology Security Assessment Framework (FITSAF), Level 4 indicates that security procedures and controls have been formally tested and thoroughly reviewed. This level signifies a high degree of assurance regarding the effectiveness of implemented…
Question
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls are tested and reviewed?
Options
- ALevel 4
- BLevel 5
- CLevel 2
- DLevel 3
- ELevel 1
How the community answered
(23 responses)- A91% (21)
- C4% (1)
- D4% (1)
Why each option
In the Federal Information Technology Security Assessment Framework (FITSAF), Level 4 indicates that security procedures and controls have been formally tested and thoroughly reviewed. This level signifies a high degree of assurance regarding the effectiveness of implemented security measures.
According to the Federal Information Technology Security Assessment Framework (FITSAF), Level 4, often referred to as "Tested and Reviewed," signifies that the organization has established and implemented security procedures and controls, and these controls have been formally tested for effectiveness and thoroughly reviewed. This level provides assurance that the security measures are not only in place but also function as intended, demonstrating a mature security posture where controls are validated through assessment.
Level 5 (Managed and Measured) typically indicates continuous monitoring, measurement, and optimization of controls, going beyond just testing and reviewing.
Level 2 (Documented) implies that procedures and controls are documented but not necessarily tested or reviewed for effectiveness.
Level 3 (Implemented) suggests that procedures and controls are in place and operational, but there might not be a formal testing and review process.
Level 1 (Ad Hoc) indicates that security processes are informal, inconsistent, and not systematically applied or documented.
Concept tested: FITSAF security assessment levels
Topics
Community Discussion
No community discussion yet for this question.