nerdexam
(ISC)2

CSSLP · Question #271

Which of the following NIST Special Publication documents provides a guideline on questionnaires and checklists through which systems can be evaluated for compliance against specific control objective

The correct answer is B. NIST SP 800-26. NIST Special Publication 800-26, titled 'Security Self-Assessment Guide for Information Technology Systems,' specifically provides guidelines and methodology for evaluating system compliance against security objectives through the use of questionnaires and checklists.

Secure Software Deployment, Operations, Maintenance

Question

Which of the following NIST Special Publication documents provides a guideline on questionnaires and checklists through which systems can be evaluated for compliance against specific control objectives?

Options

  • ANIST SP 800-37
  • BNIST SP 800-26
  • CNIST SP 800-53A
  • DNIST SP 800-59
  • ENIST SP 800-53
  • FNIST SP 800-60

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    96% (22)

Why each option

NIST Special Publication 800-26, titled 'Security Self-Assessment Guide for Information Technology Systems,' specifically provides guidelines and methodology for evaluating system compliance against security objectives through the use of questionnaires and checklists.

ANIST SP 800-37

NIST SP 800-37 outlines the overall Risk Management Framework process, not specific guidance on using questionnaires and checklists for assessment.

BNIST SP 800-26Correct

NIST SP 800-26 offers a framework for organizations to perform security self-assessments, providing questionnaires and checklists to systematically evaluate their information systems against established security controls and objectives to determine compliance.

CNIST SP 800-53A

NIST SP 800-53A focuses on assessment procedures and methods for security controls, which are more comprehensive than just questionnaires and checklists.

DNIST SP 800-59

NIST SP 800-59 provides guidance on identifying national security systems, which is unrelated to assessment questionnaires and checklists.

ENIST SP 800-53

NIST SP 800-53 lists the actual security controls, but does not provide guidance on how to use questionnaires to evaluate them.

FNIST SP 800-60

NIST SP 800-60 details the process for categorizing information and systems, which is not about evaluating compliance via questionnaires.

Concept tested: NIST SP 800-26 - Self-Assessment Guidelines

Source: https://csrc.nist.gov/publications/detail/sp/800-26/archive/1999-11-01

Topics

#NIST SP 800-26#Security Assessment#Compliance Evaluation#IT System Evaluation

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice