nerdexam
(ISC)2

CSSLP · Question #267

Which of the following documents were developed by NIST for conducting Certification & Accreditation (C&A)? Each correct answer represents a complete solution. Choose all that apply.

The correct answer is A. NIST Special Publication 800-60 B. NIST Special Publication 800-53 D. NIST Special Publication 800-59 E. NIST Special Publication 800-37 F. NIST Special Publication 800-53A. NIST Special Publications 800-37, 800-53, 800-53A, 800-60, and 800-59 are key documents developed by NIST that provide guidance and standards for conducting Certification & Accreditation (C&A), now known as the Risk Management Framework (RMF). These publications cover various asp

Secure Software Lifecycle Management

Question

Which of the following documents were developed by NIST for conducting Certification & Accreditation (C&A)? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ANIST Special Publication 800-60
  • BNIST Special Publication 800-53
  • CNIST Special Publication 800-37A
  • DNIST Special Publication 800-59
  • ENIST Special Publication 800-37
  • FNIST Special Publication 800-53A

How the community answered

(47 responses)
  • A
    91% (43)
  • C
    9% (4)

Why each option

NIST Special Publications 800-37, 800-53, 800-53A, 800-60, and 800-59 are key documents developed by NIST that provide guidance and standards for conducting Certification & Accreditation (C&A), now known as the Risk Management Framework (RMF). These publications cover various aspects from framework application to control selection and assessment.

ANIST Special Publication 800-60Correct

NIST SP 800-60, 'Guide for Mapping Types of Information and Information Systems to Security Categories,' is used in the C&A process to categorize information and systems based on their potential impact levels, which is a foundational step.

BNIST Special Publication 800-53Correct

NIST SP 800-53, 'Security and Privacy Controls for Federal Information Systems and Organizations,' provides the comprehensive catalog of security controls that agencies select and implement during C&A to protect their systems.

CNIST Special Publication 800-37A

NIST Special Publication 800-37A is not a recognized or existing NIST publication in the 800 series; the primary related document for the Risk Management Framework is NIST SP 800-37.

DNIST Special Publication 800-59Correct

NIST SP 800-59, 'Guideline for Identifying an Information System as a National Security System,' aids in determining if a system falls under national security jurisdiction, which impacts its C&A requirements and process.

ENIST Special Publication 800-37Correct

NIST SP 800-37, 'Guide for Applying the Risk Management Framework to Federal Information Systems and Organizations,' serves as the foundational document outlining the entire C&A/RMF process, including its steps and activities.

FNIST Special Publication 800-53ACorrect

NIST SP 800-53A, 'Assessing Security and Privacy Controls in Federal Information Systems and Organizations,' provides guidance on how to assess the effectiveness of the security controls chosen from SP 800-53 during C&A to ensure they meet requirements.

Concept tested: NIST Special Publications for C&A/RMF

Source: https://csrc.nist.gov/publications/sp

Topics

#NIST SP 800 Series#Risk Management Framework (RMF)#Certification & Accreditation (C&A)#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice