nerdexam
(ISC)2

CSSLP · Question #284

Which of the following US Acts emphasized a "risk-based policy for cost-effective security" and makes mandatory for agency program officials, chief information officers, and inspectors general (IGs) t

The correct answer is A. Federal Information Security Management Act of 2002 (FISMA). The Federal Information Security Management Act (FISMA) mandates a risk-based approach to information security for federal agencies, requiring annual reviews and reporting to the OMB.

Secure Software Lifecycle Management

Question

Which of the following US Acts emphasized a "risk-based policy for cost-effective security" and makes mandatory for agency program officials, chief information officers, and inspectors general (IGs) to conduct annual reviews of the agency's information security program and report the results to Office of Management and Budget?

Options

  • AFederal Information Security Management Act of 2002 (FISMA)
  • BThe Electronic Communications Privacy Act of 1986 (ECPA)
  • CThe Equal Credit Opportunity Act (ECOA)
  • DThe Fair Credit Reporting Act (FCRA)

How the community answered

(28 responses)
  • A
    89% (25)
  • C
    7% (2)
  • D
    4% (1)

Why each option

The Federal Information Security Management Act (FISMA) mandates a risk-based approach to information security for federal agencies, requiring annual reviews and reporting to the OMB.

AFederal Information Security Management Act of 2002 (FISMA)Correct

The Federal Information Security Management Act (FISMA) of 2002 established a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support federal operations and assets. It specifically requires federal agencies to develop, document, and implement an agency-wide information security program, including annual reviews and reporting to the Office of Management and Budget (OMB), emphasizing a risk-based policy.

BThe Electronic Communications Privacy Act of 1986 (ECPA)

The Electronic Communications Privacy Act (ECPA) primarily addresses the privacy of electronic communications, not federal information security program management and reporting.

CThe Equal Credit Opportunity Act (ECOA)

The Equal Credit Opportunity Act (ECOA) prohibits discrimination in credit transactions, which is unrelated to federal information security.

DThe Fair Credit Reporting Act (FCRA)

The Fair Credit Reporting Act (FCRA) regulates the collection, dissemination, and use of consumer credit information, not federal agency information security programs.

Concept tested: US Federal IT Security Regulations - FISMA

Source: https://csrc.nist.gov/projects/federal-information-security-modernization-act-fisma

Topics

#FISMA#Information Security Governance#Compliance#Risk Management

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice