nerdexam
GIAC

GCIH · Question #71

Which of the following US Acts emphasized a "risk-based policy for cost-effective security" and makes mandatory for agency program officials, chief information officers, and inspectors general (IGs)…

The correct answer is D. Federal Information Security Management Act of 2002 (FISMA). FISMA 2002 is the US federal law that established a risk-based framework for agency information security and created mandatory annual review and OMB reporting requirements.

Incident Response & Cyber Kill Chain

Question

Which of the following US Acts emphasized a "risk-based policy for cost-effective security" and makes mandatory for agency program officials, chief information officers, and inspectors general (IGs) to conduct annual reviews of the agency's information security program and report the results to Office of Management and Budget?

Options

  • AThe Electronic Communications Privacy Act of 1986 (ECPA)
  • BThe Fair Credit Reporting Act (FCRA)
  • CThe Equal Credit Opportunity Act (ECOA)
  • DFederal Information Security Management Act of 2002 (FISMA)

How the community answered

(63 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    3% (2)
  • D
    92% (58)

Why each option

FISMA 2002 is the US federal law that established a risk-based framework for agency information security and created mandatory annual review and OMB reporting requirements.

AThe Electronic Communications Privacy Act of 1986 (ECPA)

The Electronic Communications Privacy Act of 1986 governs law enforcement access to stored electronic communications and wiretapping - it contains no provisions about federal agency security program reviews or OMB reporting.

BThe Fair Credit Reporting Act (FCRA)

The Fair Credit Reporting Act regulates how consumer credit information is collected and used by credit reporting agencies, and has no bearing on federal information security management or annual security assessments.

CThe Equal Credit Opportunity Act (ECOA)

The Equal Credit Opportunity Act prohibits discrimination in credit decisions based on protected characteristics and is entirely unrelated to government information security programs or agency review requirements.

DFederal Information Security Management Act of 2002 (FISMA)Correct

FISMA (Federal Information Security Management Act of 2002) explicitly requires agency program officials, CIOs, and Inspectors General to conduct annual reviews of the information security program and report findings to the Office of Management and Budget, all grounded in a risk-based, cost-effective security philosophy rather than a compliance-checkbox approach.

Concept tested: FISMA 2002 requirements for federal agency security programs

Source: https://csrc.nist.gov/topics/laws-and-regulations/laws/fisma

Topics

#FISMA#security compliance legislation#risk-based policy#federal security

Community Discussion

No community discussion yet for this question.

Full GCIH Practice