QA from FITSP - Manager, Next Generation Exam (Graded A)
QA from FITSP - Manager, Next Generation Exam (Graded A) The following legislation requires federal agencies to develop, document and implement an agency-wide information security program: - Answer ️️ -FISMA The following legislation requires each agency with an Inspector General to conduct an annual evaluation of agency's information security program, or to appoint an independent external auditor, to conduct the evaluation on their behalf - Answer ️️ -E-Government Act of 2002, Section 208 The following OMB guidance established the requirement for federal agencies to review the security controls in each system when significant modifications are made to the system, or at least every three years. This guidance also requires federal agencies to re-authorize information systems every three years - Answer ️️ -OMB Circular No. A-130, Appendix III, Security of Federal Automated Information Resources The Federal Information Security Modernization Act of 2014 (FISMA 2014) formally assigns information security responsibilities to which of the following agencies/departments (select two): - Answer ️️ -DHS and OMB Current regulations still require the re-authorization of federal information systems at least every three years. - Answer ️️ -True The following OMB guidance established the requirement for federal agencies to review the security controls in each system when significant modifications are made to the system, but at least every three years. This guidance also requires federal agencies to re-authorize information systems every three years. - Answer ️️ -OMB Circular No. A-130, Appendix III, Security of Federal Automated Information Resources As part of monitoring the security posture of agency desktops, OMB requires federal agencies to use vulnerability scanning tools that leverage the ________ protocol. - Answer ️️ -SCAP Following the loss of 26 million records containing PII at the Department of Veteran Affairs, OMB released M-06-16 Protection of Sensitive Agency Information. This memo required all of the following EXCEPT: - Answer ️️ -Encryption of all server backup tapes This Homeland Security Presidential Directive requires all federal agencies to adopt a standard, government wide card to reduce identity fraud, protect personal privacy, and provide for authentication. This directive was called: - Answer ️️ -HSPD-12 - Common Identification Standard Current regulations still require the re-authorization of federal information systems at least every three years. - Answer ️️ -True What elements are components of an information system? - Answer ️️ -Hardware and software, Interconnected systems, People What is the main consideration in determining the scope of authorization for information systems? - Answer ️️ -System Boundaries Which approach involves continually balancing the protection of agency information and assets with the cost of security controls and mitigation strategies? - Answer ️️ -Risk Management Approach What establishes the scope of protection for organizational information systems? - Answer ️️ - System Bound
Document information
- Uploaded on
- January 19, 2024
- Number of pages
- 12
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers