nerdexam
(ISC)2

CSSLP · Question #232

FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that…

The correct answer is A. Level 4. In the Federal Information Technology Security Assessment Framework (FITSAF), Level 4 indicates that security procedures and controls have been formally tested and thoroughly reviewed. This level signifies a high degree of assurance regarding the effectiveness of implemented…

Secure Software Lifecycle Management

Question

FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls are tested and reviewed?

Options

  • ALevel 4
  • BLevel 5
  • CLevel 2
  • DLevel 3
  • ELevel 1

How the community answered

(23 responses)
  • A
    91% (21)
  • C
    4% (1)
  • D
    4% (1)

Why each option

In the Federal Information Technology Security Assessment Framework (FITSAF), Level 4 indicates that security procedures and controls have been formally tested and thoroughly reviewed. This level signifies a high degree of assurance regarding the effectiveness of implemented security measures.

ALevel 4Correct

According to the Federal Information Technology Security Assessment Framework (FITSAF), Level 4, often referred to as "Tested and Reviewed," signifies that the organization has established and implemented security procedures and controls, and these controls have been formally tested for effectiveness and thoroughly reviewed. This level provides assurance that the security measures are not only in place but also function as intended, demonstrating a mature security posture where controls are validated through assessment.

BLevel 5

Level 5 (Managed and Measured) typically indicates continuous monitoring, measurement, and optimization of controls, going beyond just testing and reviewing.

CLevel 2

Level 2 (Documented) implies that procedures and controls are documented but not necessarily tested or reviewed for effectiveness.

DLevel 3

Level 3 (Implemented) suggests that procedures and controls are in place and operational, but there might not be a formal testing and review process.

ELevel 1

Level 1 (Ad Hoc) indicates that security processes are informal, inconsistent, and not systematically applied or documented.

Concept tested: FITSAF security assessment levels

Topics

#FITSAF#Security Assessment Frameworks#Security Controls Testing#Security Program Maturity

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice