CSSLP · Question #37
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that t
The correct answer is B. Level 3. This question asks to identify the specific level within the Federal Information Technology Security Assessment Framework (FITSAF) where security procedures and controls are confirmed to be operational.
Question
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls have been implemented?
Options
- ALevel 2
- BLevel 3
- CLevel 5
- DLevel 1
- ELevel 4
How the community answered
(28 responses)- A4% (1)
- B86% (24)
- C7% (2)
- D4% (1)
Why each option
This question asks to identify the specific level within the Federal Information Technology Security Assessment Framework (FITSAF) where security procedures and controls are confirmed to be operational.
Level 2 ('Documented') indicates that security procedures and controls have been formally written down, but it does not confirm that they have been deployed or are actively functioning.
FITSAF Level 3, termed 'Implemented,' signifies that the security procedures and controls, which were previously documented and designed, have now been successfully put into active operation within the information system.
Level 5 ('Measured') means that implemented controls are not only operational but are also continuously monitored, evaluated, and improved, which is a stage beyond mere implementation.
Level 1 ('Defined') suggests that the organization has identified the general need for security controls but has not yet developed or documented specific procedures.
Level 4 ('Tested') implies that the implemented controls have undergone formal testing and evaluation to ensure their effectiveness, which is a step further than simply being implemented.
Concept tested: FITSAF assessment levels
Source: https://www.sec.gov/oig/audit/2004/audit-240.pdf
Topics
Community Discussion
No community discussion yet for this question.