nerdexam
(ISC)2

CSSLP · Question #313

Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the f

The correct answer is A. IR Incident Response C. SA System and Services Acquisition D. CA Certification, Accreditation, and Security Assessments. US Federal Government information security standards, particularly NIST SP 800-53, include control families such as IR (Incident Response), SA (System and Services Acquisition), and CA (Certification, Accreditation, and Security Assessments).

Secure Software Lifecycle Management

Question

Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the following are the U.S. Federal Government information security standards? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AIR Incident Response
  • BInformation systems acquisition, development, and maintenance
  • CSA System and Services Acquisition
  • DCA Certification, Accreditation, and Security Assessments

How the community answered

(31 responses)
  • A
    90% (28)
  • B
    10% (3)

Why each option

US Federal Government information security standards, particularly NIST SP 800-53, include control families such as IR (Incident Response), SA (System and Services Acquisition), and CA (Certification, Accreditation, and Security Assessments).

AIR Incident ResponseCorrect

IR (Incident Response) is a control family within NIST SP 800-53, outlining requirements for developing and implementing incident response capabilities.

BInformation systems acquisition, development, and maintenance

'Information systems acquisition, development, and maintenance' describes a general process or category, but it is not one of the specific, recognized two-letter acronym control families used in NIST SP 800-53.

CSA System and Services AcquisitionCorrect

SA (System and Services Acquisition) is a control family in NIST SP 800-53, addressing the security aspects of acquiring, developing, and maintaining information systems and services.

DCA Certification, Accreditation, and Security AssessmentsCorrect

CA (Certification, Accreditation, and Security Assessments) is a control family within NIST SP 800-53, focusing on assessing and authorizing information systems.

Concept tested: NIST SP 800-53 control families

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev5/final

Topics

#NIST SP 800-53#Federal Standards#Security Controls#Risk Management Framework

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice