nerdexam
(ISC)2

CSSLP · Question #74

You work as a security engineer for BlueWell Inc. Which of the following documents will you use as a guide for the security certification and accreditation of Federal Information Systems?

The correct answer is C. NIST Special Publication 800-37. For guiding security certification and accreditation (C&A), specifically the Risk Management Framework (RMF) for federal information systems, NIST Special Publication 800-37 is the authoritative document.

Secure Software Deployment, Operations, Maintenance

Question

You work as a security engineer for BlueWell Inc. Which of the following documents will you use as a guide for the security certification and accreditation of Federal Information Systems?

Options

  • ANIST Special Publication 800-60
  • BNIST Special Publication 800-53
  • CNIST Special Publication 800-37
  • DNIST Special Publication 800-59

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    87% (27)
  • D
    6% (2)

Why each option

For guiding security certification and accreditation (C&A), specifically the Risk Management Framework (RMF) for federal information systems, NIST Special Publication 800-37 is the authoritative document.

ANIST Special Publication 800-60

NIST Special Publication 800-60 focuses on categorizing information systems based on impact levels, which is an input to the RMF but not the guide for the C&A process itself.

BNIST Special Publication 800-53

NIST Special Publication 800-53 provides a catalog of security and privacy controls, which are implemented and assessed during the RMF process, but it is not the guide for the overarching C&A process.

CNIST Special Publication 800-37Correct

NIST Special Publication 800-37, titled "Guide for Applying the Risk Management Framework to Federal Information Systems," provides the comprehensive process and guidelines for the security certification and accreditation (C&A) of federal information systems. It details the steps of the Risk Management Framework (RMF), which replaced earlier C&A processes for federal agencies.

DNIST Special Publication 800-59

NIST Special Publication 800-59 specifically addresses criteria for designating national security systems, which is a classification, not the C&A process.

Concept tested: NIST SPs for C&A/RMF

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST SP 800-37#Risk Management Framework (RMF)#Security Authorization#Certification & Accreditation (C&A)

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice