Exam Questions and CORRECT Answers
FIPS 199 - CORRECT ANSWER - Standards for Security Categorization of Federal
Information and Information Systems.
Sec categorization -- first step in risk mgmt process, must be accomplished as an enterprise-wide
activity with the involvement of senior-level officials, but not limited to, CIO, ISO, AO, info
owner.
FIPS 200 - CORRECT ANSWER - Minimum Security Requirements for Federal
Information and Information Systems.
Select appropriate set of sec controls.
SP 800-18 - CORRECT ANSWER - Guide for Developing Security Plans for Federal
Information Systems
*System Security Plan*
SP 800-30 - CORRECT ANSWER - Guide for Conducting Risk Assessments
SP 800-37 - CORRECT ANSWER - Guide for Applying the Risk Management
Framework to Federal Information Systems: A security Life Cycle Approach.
*RMF Roles and Process*
SP 800-39 - CORRECT ANSWER - Managing Information Security Risk: Organization,
Mission, and Information System View.
SP 800-41 - CORRECT ANSWER - Guide on Firewalls and Firewall Policy
SP 800-47 - CORRECT ANSWER - Security Guide for Interconnecting Information
Technology Systems