CSSLP · Question #267
Which of the following documents were developed by NIST for conducting Certification & Accreditation (C&A)? Each correct answer represents a complete solution. Choose all that apply.
The correct answer is A. NIST Special Publication 800-60 B. NIST Special Publication 800-53 D. NIST Special Publication 800-59 E. NIST Special Publication 800-37 F. NIST Special Publication 800-53A. NIST Special Publications 800-37, 800-53, 800-53A, 800-60, and 800-59 are key documents developed by NIST that provide guidance and standards for conducting Certification & Accreditation (C&A), now known as the Risk Management Framework (RMF). These publications cover various asp
Question
Which of the following documents were developed by NIST for conducting Certification & Accreditation (C&A)? Each correct answer represents a complete solution. Choose all that apply.
Options
- ANIST Special Publication 800-60
- BNIST Special Publication 800-53
- CNIST Special Publication 800-37A
- DNIST Special Publication 800-59
- ENIST Special Publication 800-37
- FNIST Special Publication 800-53A
How the community answered
(47 responses)- A91% (43)
- C9% (4)
Why each option
NIST Special Publications 800-37, 800-53, 800-53A, 800-60, and 800-59 are key documents developed by NIST that provide guidance and standards for conducting Certification & Accreditation (C&A), now known as the Risk Management Framework (RMF). These publications cover various aspects from framework application to control selection and assessment.
NIST SP 800-60, 'Guide for Mapping Types of Information and Information Systems to Security Categories,' is used in the C&A process to categorize information and systems based on their potential impact levels, which is a foundational step.
NIST SP 800-53, 'Security and Privacy Controls for Federal Information Systems and Organizations,' provides the comprehensive catalog of security controls that agencies select and implement during C&A to protect their systems.
NIST Special Publication 800-37A is not a recognized or existing NIST publication in the 800 series; the primary related document for the Risk Management Framework is NIST SP 800-37.
NIST SP 800-59, 'Guideline for Identifying an Information System as a National Security System,' aids in determining if a system falls under national security jurisdiction, which impacts its C&A requirements and process.
NIST SP 800-37, 'Guide for Applying the Risk Management Framework to Federal Information Systems and Organizations,' serves as the foundational document outlining the entire C&A/RMF process, including its steps and activities.
NIST SP 800-53A, 'Assessing Security and Privacy Controls in Federal Information Systems and Organizations,' provides guidance on how to assess the effectiveness of the security controls chosen from SP 800-53 during C&A to ensure they meet requirements.
Concept tested: NIST Special Publications for C&A/RMF
Source: https://csrc.nist.gov/publications/sp
Topics
Community Discussion
No community discussion yet for this question.