PROGRAM AWARENESS AND RISK
MANAGEMENT | QUESTIONS AND
ANSWERS | 2026 UPDATE | WITH
COMPLETE SOLUTIONS.
Authenticity - answer- The property of being genuine and able to be verified and trusted;
confidence in the validity of a transmission, a message, or message originator. (Source:
NIST SP 800-53 Rev 4; NIST SP 800-53A Rev 1; NIST SP 800-39.) Authenticity is
assurance that a message does indeed come from the person who claims to have sent
it.
Availability - answer- Ensuring timely and reliable access to and use of information.
Compliance - answer- Adherence to a mandate; both the actions demonstrating
adherence and the tools, processes, and documentation that are used in adherence.
Confidentiality - answer- Preserving authorized restrictions on information access and
disclosure, including means for protecting personal privacy and proprietary information.
Data at rest - answer- Data that is in storage. It is not being accessed or used.
Data in transit - answer- Data that is currently traveling from one system or device to
another; also known as data in motion.
Data in use - answer- Data that is being processed, read, accessed, erased, or updated
by a system.
Governance - answer- The process of how an organization is managed; usually
includes all aspects of how decisions are made for that organization, such as policies,
roles, and procedures the organization uses to make those decisions.
Intangible asset - answer- Asset that has value but may not have a physical presence.
Integrity - answer- Guarding against improper information modification or destruction;
includes ensuring information nonrepudiation and authenticity.
Nonrepudiation - answer- Protection against an individual falsely denying having
performed a particular action. Nonrepudiation provides the capability to determine