• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 9 pages
Exam (elaborations)

NIST SP 800-53 UPDATED ACTUAL Exam Questions and CORRECT Answers

Document preview thumbnail
Preview 2 out of 9 pages

NIST SP 800-53 UPDATED ACTUAL Exam Questions and CORRECT Answers security controls - CORRECT ANSWER - important tasks that can have major implications on the operations and assets of organizations as well as the welfare of individuals and the Nation security controls - CORRECT ANSWER - safeguards/countermeasures prescribed for information systems or organizations that are designed to: (i) protect the confidentiality, integrity, and availability of information that is processed, stored, and transmitted by those systems/organizations; and (ii) satisfy a set of defined security requirements.

Content preview

NIST SP 800-53 UPDATED ACTUAL Exam
Questions and CORRECT Answers
security controls - CORRECT ANSWER - important tasks that can have major
implications on the operations and assets of organizations as well as the welfare of individuals
and the Nation


security controls - CORRECT ANSWER - safeguards/countermeasures prescribed for
information systems or organizations that are designed to: (i) protect the confidentiality,
integrity, and availability of information that is processed, stored, and transmitted by those
systems/organizations; and (ii) satisfy a set of defined security requirements.


NIST Special Publication 800-39 - CORRECT ANSWER - provides guidance on
managing information security risk at three distinct tiers—the organization level,
mission/business process level, and information system level.


OMB Circular A-130 - CORRECT ANSWER - defines as adequate security, or security
commensurate with risk resulting from the unauthorized access, use, disclosure, disruption,
modification, or destruction of information.


three-tiered approach to risk managment - CORRECT ANSWER - addresses risk at the: (i)
organization level; (ii) mission/business process level; and (iii) information system level.


Tier 1 Organization Level - CORRECT ANSWER - provides a prioritization of
organizational missions/business functions which in turn drives investment strategies and
funding decisions—promoting cost-effective, efficient information technology solutions
consistent with the strategic goals and objectives of the organization and measures of
performance.


Tier 2, Mission /Business Process - CORRECT ANSWER - (i) defining the
mission/business processes needed to support the organizational missions/business functions; (ii)
determining the security categories of the information systems needed to execute the
mission/business processes; (iii) incorporating information security requirements into the
mission/business processes; and (iv) establishing an enterprise architecture (including an

, embedded information security architecture) to facilitate the allocation of security controls to
organizational information systems and the environments in which those systems operate.


Tier 3, Information Systems - CORRECT ANSWER - This publication focuses on Step 2
of the RMF, the security control selection process, in the context of the three tiers in the
organizational risk management hierarchy.


Three-Tiered Risk Management Approach - CORRECT ANSWER -



Risk Management Framework - CORRECT ANSWER -



RMF Step 1: Categorize - CORRECT ANSWER - RMF step in which information
systems are classified based on a FIPS Publication 199 impact assessment


RMF Step 2: Select - CORRECT ANSWER - RMF step in which security control
baselines are based on the results of the security categorization and apply tailoring guidance
(including the potential use of overlays)


RMF Step 3: Implement - CORRECT ANSWER - RMF step that directs the
documentation the design, development, and implementation details for the controls.


RMF Step 4: Assess - CORRECT ANSWER - RMF step that is used to determine the
extent to which the controls are implemented correctly, operating as intended, and producing the
desired outcome with respect to meeting the security requirements for the system


RMF Step 5: Authorize - CORRECT ANSWER - RMF step in which system operation is
based on a determination of risk to organizational operations and assets, individuals, other
organizations, and the Nation resulting from the operation and use of the information system and
the decision that this risk is acceptable


RMF Step 6: Monitor - CORRECT ANSWER - RMF step where the security controls in
the information system and environment of operation are checked on an ongoing basis to

Document information

Uploaded on
May 4, 2025
Number of pages
9
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$12.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STANFORDGRADESS
4.0
(239)
Sold
1627
Followers
108
Items
116143
Last sold
15 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions