nerdexam
(ISC)2

CSSLP · Question #257

You work as a security engineer for BlueWell Inc. You want to use some techniques and procedures to verify the effectiveness of security controls in Federal Information System. Which of the…

The correct answer is C. NIST Special Publication 800-53A. The question seeks the NIST document that provides techniques and procedures for verifying the effectiveness of security controls in federal information systems.

Secure Software Testing

Question

You work as a security engineer for BlueWell Inc. You want to use some techniques and procedures to verify the effectiveness of security controls in Federal Information System. Which of the following NIST documents will guide you?

Options

  • ANIST Special Publication 800-53
  • BNIST Special Publication 800-59
  • CNIST Special Publication 800-53A
  • DNIST Special Publication 800-37

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    90% (35)
  • D
    3% (1)

Why each option

The question seeks the NIST document that provides techniques and procedures for verifying the effectiveness of security controls in federal information systems.

ANIST Special Publication 800-53

NIST Special Publication 800-53 provides a catalog of security and privacy controls for federal information systems, not the assessment procedures.

BNIST Special Publication 800-59

NIST Special Publication 800-59 defines the critical assets within federal information systems, not the assessment procedures for security controls.

CNIST Special Publication 800-53ACorrect

NIST Special Publication 800-53A provides guidelines for assessing the security controls implemented in federal information systems and organizations. It outlines the specific techniques and procedures for verifying the effectiveness of these controls as defined in NIST SP 800-53.

DNIST Special Publication 800-37

NIST Special Publication 800-37 outlines the Risk Management Framework (RMF) for federal information systems, which includes steps like categorization, selection, implementation, assessment, authorization, and monitoring, but 800-53A focuses specifically on the assessment phase.

Concept tested: NIST SP 800-53A security control assessment

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf

Topics

#NIST SP 800-53A#Security Control Assessment#Federal Information Systems#Compliance

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice