CSSLP · Question #271
Which of the following NIST Special Publication documents provides a guideline on questionnaires and checklists through which systems can be evaluated for compliance against specific control objective
The correct answer is B. NIST SP 800-26. NIST Special Publication 800-26, titled 'Security Self-Assessment Guide for Information Technology Systems,' specifically provides guidelines and methodology for evaluating system compliance against security objectives through the use of questionnaires and checklists.
Question
Which of the following NIST Special Publication documents provides a guideline on questionnaires and checklists through which systems can be evaluated for compliance against specific control objectives?
Options
- ANIST SP 800-37
- BNIST SP 800-26
- CNIST SP 800-53A
- DNIST SP 800-59
- ENIST SP 800-53
- FNIST SP 800-60
How the community answered
(23 responses)- A4% (1)
- B96% (22)
Why each option
NIST Special Publication 800-26, titled 'Security Self-Assessment Guide for Information Technology Systems,' specifically provides guidelines and methodology for evaluating system compliance against security objectives through the use of questionnaires and checklists.
NIST SP 800-37 outlines the overall Risk Management Framework process, not specific guidance on using questionnaires and checklists for assessment.
NIST SP 800-26 offers a framework for organizations to perform security self-assessments, providing questionnaires and checklists to systematically evaluate their information systems against established security controls and objectives to determine compliance.
NIST SP 800-53A focuses on assessment procedures and methods for security controls, which are more comprehensive than just questionnaires and checklists.
NIST SP 800-59 provides guidance on identifying national security systems, which is unrelated to assessment questionnaires and checklists.
NIST SP 800-53 lists the actual security controls, but does not provide guidance on how to use questionnaires to evaluate them.
NIST SP 800-60 details the process for categorizing information and systems, which is not about evaluating compliance via questionnaires.
Concept tested: NIST SP 800-26 - Self-Assessment Guidelines
Source: https://csrc.nist.gov/publications/detail/sp/800-26/archive/1999-11-01
Topics
Community Discussion
No community discussion yet for this question.