nerdexam
(ISC)2

CSSLP · Question #274

Which of the following security objectives are defined for information and information systems by the FISMA? Each correct answer represents a part of the solution. Choose all that apply.

The correct answer is B. Availability C. Integrity D. Confidentiality. The Federal Information Security Modernization Act (FISMA) defines the primary security objectives for federal information and information systems as Confidentiality, Integrity, and Availability, commonly known as the CIA triad. These objectives aim to protect information from…

Secure Software Concepts

Question

Which of the following security objectives are defined for information and information systems by the FISMA? Each correct answer represents a part of the solution. Choose all that apply.

Options

  • AAuthenticity
  • BAvailability
  • CIntegrity
  • DConfidentiality

How the community answered

(23 responses)
  • A
    13% (3)
  • B
    87% (20)

Why each option

The Federal Information Security Modernization Act (FISMA) defines the primary security objectives for federal information and information systems as Confidentiality, Integrity, and Availability, commonly known as the CIA triad. These objectives aim to protect information from unauthorized access, modification, and disruption.

AAuthenticity

Authenticity, while an important security attribute, is typically considered a supporting control or characteristic for ensuring integrity and non-repudiation, rather than one of the three primary, overarching security objectives (Confidentiality, Integrity, Availability) defined by FISMA.

BAvailabilityCorrect

Availability, as a core FISMA objective, ensures that authorized users have timely and reliable access to information and information systems when needed, preventing service denial.

CIntegrityCorrect

Integrity, another primary FISMA objective, involves safeguarding the accuracy and completeness of information and protecting it from unauthorized modification or destruction.

DConfidentialityCorrect

Confidentiality, a key FISMA objective, protects sensitive information from unauthorized access and disclosure, ensuring only authorized entities can view or read it.

Concept tested: FISMA security objectives (CIA triad)

Source: https://csrc.nist.gov/glossary/term/information_security

Topics

#FISMA#Security Objectives#Confidentiality Integrity Availability

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice