and CORRECT Answers
NIST 800-55 - CORRECT ANSWER - A NIST standard for PERFORMANCE
MEASUREMENT for information security.
NIST 800-30 - CORRECT ANSWER - "Risk Management Guide for Developing a
Contingency Plan for Information Technology Systems."
NIST 800-30 - CORRECT ANSWER - A NIST standard on risk assessment specific to IT
threats. It does not cover larger organizational threat types, but focuses on the operational
components of an enterprise, not necessarily the higher strategic level.
NIST 800-66r1 - CORRECT ANSWER - NIST standard written specifically with HIPAA
clients in mind.
NIST 800-39 - CORRECT ANSWER - NIST standard focused on organizational risk
management.
NIST 800-53 - CORRECT ANSWER - It is a set of control objectivesthat agencies need to
put into place to be compliant with FISMA. Control categories are the management, operational,
technical controls.
NIST Risk Management Framework (RMF)- NIST SP 800-37 Revision 1, Guide for Applying
the Risk Management Framework to Federal Information Systems: a Security Life Cycle
Approach, - CORRECT ANSWER - A methodology which provides a disciplined and
structured process that integrates information security and risk management activities into the
system development life cycle.
NIST SP 800-40 Revision 3 - CORRECT ANSWER - Guide to Enterprise Patch
Management Technologies