FITSP-A Exam Questions and Answers
FITSP-A Exam Questions and Answers What elements are components of an information system? - Answer ️️ -OMB Circular A-130, App III: "A system normally includes hardware, software, information, data, applications, communications, and people." What are some of the threats that the information system faces? - Answer ️️ -NIST SP 800- 39rl, p. 1: "Threats to information and information systems can include purposeful attacks, environmental disruptions, and human/machine errors and result in great harm to the national and economic security interests of the United States." During what phase of the SDLC should the organization consider the security requirements (mark all that apply)? - Answer ️️ -Initiation Phase / Development / Acquisition Phase,Implementation Phase, Operation / Maintenance Phase, System Disposal Phase The PIA, BIA and Security Categorisation are all done in this phase of the SDLC: - Answer ️️ - Initiation Security Reauthorizations are conducted during which phase of the SDLC? - Answer ️️ - Operations/Maintenance Which approach involves continually balancing the protection of agency Information and assets with the cost of security controls and mitigation strategies? - Answer ️️ -Risk Management Approach Which of the following must be assigned to government personnel only (select all that apply)? - Answer ️️ -SISO and AO Place the 4 components of risk management in the correct order. - Answer ️️ -Frame, Assess, Respond, Monitor (FARM) The following are the possible outcomes of the Authorization Decision (mark all that apply): - Answer ️️ -ATO and Not authorized to operate List the 6 steps of the RMF process? - Answer ️️ -Categorize, Select, Implement, Assess, Authorize, Monitor What NIST Special Publication superseded the original Special Publication 800-30 as the source for guidance on risk management? - Answer ️️ -SP 800-39 The risk management processes, at the information system level, link to risk management processes at the organization level through what newly defined role in the RMF? - Answer ️️ - Risk Executive (Function) Applying the first three steps in the RMF to legacy systems can be viewed as a _______________ to determine if the necessary and sufficient security controls have been appropriately selected and allocated. - Answer ️️ -Gap Analysis What establishes the scope of protection for organizational information systems? - Answer ️️ - System Boundaries Name the factors that influence the level of effort expended when implementing the RMF tasks? - Answer ️️ -"Importance of the System, Criticality of the System, Categorization of the System" The Risk Management Framework (RMF) places heavy emphasis on - Answer ️️ -Selection, implementation and monitoring of security co
Document information
- Uploaded on
- January 26, 2024
- Number of pages
- 20
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers