Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Examen

RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS WITH COMPLETE SOLUTIONS

Puntuación
-
Vendido
-
Páginas
5
Grado
A+
Subido en
26-04-2025
Escrito en
2024/2025

RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS WITH COMPLETE SOLUTIONSRMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS WITH COMPLETE SOLUTIONS Agencies are required to use FIPS _____/NIST SP 800-__ for the specification of security controls and NIST SP 800-___ for the assessment of security control effectiveness. - ANSWER-200/53/53A ___________________ the security controls is using the appropriate assessment procedures to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the securing requirements for the system. - ANSWER-Assessing *An assessment can be Satisfactory (met control) or __________ (did not meet control); nothing else. DoD calls these Compliant of Non-compliant. - ANSWER-*Other

Mostrar más Leer menos
Institución
RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS
Grado
RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS

Vista previa del contenido

RMF - CHAPTER 8, STEP 4, ASSESS
SECURITY CONTROLS WITH
COMPLETE SOLUTIONS
Agencies are required to use FIPS _____/NIST SP 800-__ for the specification of
security controls and NIST SP 800-___ for the assessment of security control
effectiveness. - ANSWER-200/53/53A

___________________ the security controls is using the appropriate assessment
procedures to determine the extent to which the controls are implemented correctly,
operating as intended, and producing the desired outcome with respect to meeting the
securing requirements for the system. - ANSWER-Assessing

*An assessment can be Satisfactory (met control) or __________ (did not meet control);
nothing else. DoD calls these Compliant of Non-compliant. - ANSWER-*Other

Security weakness and deficiencies identified in the system development lifecycle can
be resolved more quickly and in a much more cost-effective manner before proceeding
to subsequent phases in the lifecycle. (True or False) - ANSWER-True

*#When iterative development processes such as ________ development are
employed, this typically results in an iterative assessment as each cycle is conducted.
(Agile = sprint/short bursts - test every cycle, iterative - agile development). - ANSWER-
*#agile

*Security Assessment Results -
Security Control Assessment Objectives:
-Implemented correctly
- Operating as intended
- Producing desired result with reference to security objectives (C, I, A). (True or False)
- ANSWER-*True

_________________ - Sprint/short burst of ..... Test every cycle - ANSWER-Agile

#Security control assessments in support of initial and subsequent security
authorization are conducted by independent assessors. Assessor independence during
continuous monitoring, although not mandated, facilitates reuse of assessment results
when ______________________ is required. - ANSWER-#reauthorization

Original Assessment Methods
*Assessment procedure steps will include the appropriate evaluation method(s) from the
following list:

, - Test (T)
- Observation (O)
- Document Review (D) = TODI
- ____________________ - ANSWER-Interview (I)

Scope, method, depth, and breath are all critical factors in _________________. -
ANSWER-assessments

6 Key Areas for _____________________
- Prepare for security control assessment
- Establish security control assessment plan
- Determine security control effectiveness
- Develop initial security assessment report
- Perform initial remediation actions
- Develop final security assessment report and addendum. - ANSWER-Assessment

Why Assess? - ANSWER-Gap Analysis (pg 345)

Security Assessment Plan -
Developing a security assessment policy
Organizations should develop an information security assessment policy to provide
direction and guidance for their security ______________________. - ANSWER-
assessments

The Assessment Plan -
The policy should be reviewed at least _________________ and whenever there are
new assessment-related requirements. - ANSWER-annually

SP800-53A
Information is more:
- Complete
- Reliable
- Trustworthy
(True or False) - ANSWER-True

The guidance in SP 800-___ have been developed to help achieve more secure
information systems within the federal government by doing the following:
- Enabling more consistent, comparable, and repeatable assessments of security
controls with reproducible results
- Facilitating more cost -effective assessment of security controls contributing to the
determination of overall control effectiveness.
- Promoting a better understanding of the risks to organizational operations,
organizational assets, individuals, other organizations, and the Nation resulting from the
operation and use of federal ISs.

Escuela, estudio y materia

Institución
RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS
Grado
RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS

Información del documento

Subido en
26 de abril de 2025
Número de páginas
5
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas

Temas

$22.49
Accede al documento completo:

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF


Documento también disponible en un lote

Thumbnail
Package deal
RISK MANAGEMENT FRAMEWORK(RMF) EXAM PACKAGE DEAL- COMPLETE BUNDLE PACK!!
-
21 2025
$ 386.29 Más información

Conoce al vendedor

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
NursingTutor1 West Virginia University
Ver perfil
Seguir Necesitas iniciar sesión para seguir a otros usuarios o asignaturas
Vendido
1673
Miembro desde
3 año
Número de seguidores
1073
Documentos
18137
Última venta
1 semana hace
Nursing Tutor

Paper Due? Worry not. Hello. Welcome to NursingTutor. Here you\'ll find verified study materials for your assignments, exams and general school work. All papers here are graded A to help you get the best grade. Also, I am a friendly person so, do not hesitate to send a message in case you have a query. I wish you Luck.

3.9

455 reseñas

5
215
4
78
3
91
2
21
1
50

Documentos populares

Recientemente visto por ti

Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes