1. must be in place for securing networks, facilities, and
systems or groups of IT systems. They are intended for technologies or system
components that are a part of the larger information security program.-
Answer Subordinate Plans
2. The term cyberwar specifically refers to conflicts between nations and their
militaries. This is the main distinction between cyberwar and other types of
information system attacks that are reported in the news media. (T or F)
Answer True
3. restrict the transmission of certain types of information to non-
U.S. citizens or non-permanent residents who are located in the United States.
Answer Export control regulations
4. Which of the following are types of export control regulations?
Answer ITAR & EAR
5. One of the most important parts of a FISMA information security program is
,that agencies test and evaluate it. FISMA requires each agency to perform
"periodic testing and evaluation of the effectiveness of information security policies,
procedures, and practices." Agencies must test every IT system—no matter the risk
level— at least once a year (T or F)Answer True
6. NIST created a FISMA Implementation Project to help it meet its FISMA du- ties.
The project helped it create FISMA-related standards and guidelines in a timely
manner. The project had two phases. In the first phase, NIST developed standards
and guidelines to help agencies meet basic FISMA requirements. The documents
developed in this phase helped agencies create their information security programs.
(T or F)
Answer True
7. An inspector general (IG) is an official who reviews the actions of a federal agency.
An IG examines the agency's activities to make sure that it's operating efficiently and
following good governance practices. (T or F)
Answer True
8. Each agency must report yearly to the OMB on its FISMA compliance activities. An
,agency also must send a copy of their yearly report to each of these agencies with the
exception ofAnswer Senate Committee on Foreign Relations
9. Congress created the in response to the September 11, 2001,
terrorist attacks.Answer FISMA
, 10. FISMA requires the Department of Commerce to create information security
standards and guidelines. To which of the following organizations did the
Department of Commerce delegate this responsibility?
Answer NIST
11. Which of the following items is not part of the in "SP 800-37, Revision 1, Guide for
Applying the Risk Management Framework to Federal Information Systems
A Security Life Cycle Approach" that NIST uses to create a risk management
framework (RMF) approach to FISMA compliance?
Answer Monitor security controls only when necessary
12. The enforces trade sanctions and embargoes.
Answer OFAC
13. Which of the following statements best captures the role and responsibility of
NIST?Answer NIST creates the standards and guidelines for non-national security systems to help agencies meet their
FISMA obligations.
14. Under FISMA, the government must have a federal incident response (IR) center.