Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS WITH COMPLETE SOLUTIONS

Rating
-
Sold
-
Pages
5
Grade
A+
Uploaded on
26-04-2025
Written in
2024/2025

RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS WITH COMPLETE SOLUTIONSRMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS WITH COMPLETE SOLUTIONS Agencies are required to use FIPS _____/NIST SP 800-__ for the specification of security controls and NIST SP 800-___ for the assessment of security control effectiveness. - ANSWER-200/53/53A ___________________ the security controls is using the appropriate assessment procedures to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the securing requirements for the system. - ANSWER-Assessing *An assessment can be Satisfactory (met control) or __________ (did not meet control); nothing else. DoD calls these Compliant of Non-compliant. - ANSWER-*Other

Show more Read less
Institution
RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS
Course
RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS

Content preview

RMF - CHAPTER 8, STEP 4, ASSESS
SECURITY CONTROLS WITH
COMPLETE SOLUTIONS
Agencies are required to use FIPS _____/NIST SP 800-__ for the specification of
security controls and NIST SP 800-___ for the assessment of security control
effectiveness. - ANSWER-200/53/53A

___________________ the security controls is using the appropriate assessment
procedures to determine the extent to which the controls are implemented correctly,
operating as intended, and producing the desired outcome with respect to meeting the
securing requirements for the system. - ANSWER-Assessing

*An assessment can be Satisfactory (met control) or __________ (did not meet control);
nothing else. DoD calls these Compliant of Non-compliant. - ANSWER-*Other

Security weakness and deficiencies identified in the system development lifecycle can
be resolved more quickly and in a much more cost-effective manner before proceeding
to subsequent phases in the lifecycle. (True or False) - ANSWER-True

*#When iterative development processes such as ________ development are
employed, this typically results in an iterative assessment as each cycle is conducted.
(Agile = sprint/short bursts - test every cycle, iterative - agile development). - ANSWER-
*#agile

*Security Assessment Results -
Security Control Assessment Objectives:
-Implemented correctly
- Operating as intended
- Producing desired result with reference to security objectives (C, I, A). (True or False)
- ANSWER-*True

_________________ - Sprint/short burst of ..... Test every cycle - ANSWER-Agile

#Security control assessments in support of initial and subsequent security
authorization are conducted by independent assessors. Assessor independence during
continuous monitoring, although not mandated, facilitates reuse of assessment results
when ______________________ is required. - ANSWER-#reauthorization

Original Assessment Methods
*Assessment procedure steps will include the appropriate evaluation method(s) from the
following list:

, - Test (T)
- Observation (O)
- Document Review (D) = TODI
- ____________________ - ANSWER-Interview (I)

Scope, method, depth, and breath are all critical factors in _________________. -
ANSWER-assessments

6 Key Areas for _____________________
- Prepare for security control assessment
- Establish security control assessment plan
- Determine security control effectiveness
- Develop initial security assessment report
- Perform initial remediation actions
- Develop final security assessment report and addendum. - ANSWER-Assessment

Why Assess? - ANSWER-Gap Analysis (pg 345)

Security Assessment Plan -
Developing a security assessment policy
Organizations should develop an information security assessment policy to provide
direction and guidance for their security ______________________. - ANSWER-
assessments

The Assessment Plan -
The policy should be reviewed at least _________________ and whenever there are
new assessment-related requirements. - ANSWER-annually

SP800-53A
Information is more:
- Complete
- Reliable
- Trustworthy
(True or False) - ANSWER-True

The guidance in SP 800-___ have been developed to help achieve more secure
information systems within the federal government by doing the following:
- Enabling more consistent, comparable, and repeatable assessments of security
controls with reproducible results
- Facilitating more cost -effective assessment of security controls contributing to the
determination of overall control effectiveness.
- Promoting a better understanding of the risks to organizational operations,
organizational assets, individuals, other organizations, and the Nation resulting from the
operation and use of federal ISs.

Written for

Institution
RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS
Course
RMF - CHAPTER 8, STEP 4, ASSESS SECURITY CONTROLS

Document information

Uploaded on
April 26, 2025
Number of pages
5
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$22.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Thumbnail
Package deal
RISK MANAGEMENT FRAMEWORK(RMF) EXAM PACKAGE DEAL- COMPLETE BUNDLE PACK!!
-
21 2025
$ 386.29 More info

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NursingTutor1 West Virginia University
View profile
Follow You need to be logged in order to follow users or courses
Sold
1673
Member since
3 year
Number of followers
1073
Documents
18137
Last sold
1 week ago
Nursing Tutor

Paper Due? Worry not. Hello. Welcome to NursingTutor. Here you\'ll find verified study materials for your assignments, exams and general school work. All papers here are graded A to help you get the best grade. Also, I am a friendly person so, do not hesitate to send a message in case you have a query. I wish you Luck.

3.9

455 reviews

5
215
4
78
3
91
2
21
1
50

Trending documents

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions