FITSP MANAGER EXAMS SCRIPT 2025/2026 QUESTIONS
WITH ANSWERS RATED A+
✔✔What does Tier 3 address? - ✔✔Tier 3 addresses risk from an information system
perspective and is guided by the risk decisions at Tiers 1 and Tier 2
✔✔What NIST SPs cover Security Architeture - ✔✔SP-800-14, SP-800-27 and SP-800-
160
✔✔What are the four component of RMF - ✔✔Frame (risk)
Assess (risk)
Respond (to risk one determied)
Monitor (risk on an ongoing basis)
✔✔Which two NIST SP provide management overview and risk assessment guidance
on risk management? - ✔✔SP-800-37R1 - Guide to Applying the Risk Management
Framework to Federal Information Systems
SP-800-39 - Managing Information Security Risk (superseded SP-800-30
✔✔What is the CIO responsibilities (government personnel only) - ✔✔Designating
Senior Information Security Officer
Information Security Policies
Ensuring Adequately trained personnel
Assisting Senior Official with their security responsibilities
Appropriate Allocation of Resources
FISMA Reporting
✔✔What is the Risk Executive (function) (government personnel only) - ✔✔Ensure risk-
related considerations are organization wide
Consistent throughout organization
Coordinates with Senior Leadership
-Provide comprehensive approach
-Develop a Risk Management Strategy
-Facilitate sharing of risk information
-Provide oversight
-Provide forum to consider all risk sources
✔✔What is the Common Control Provider responsibilities? - ✔✔Documenting common
controls
Validating Required Control Assessments
Documenting assessment findings in SAR
Producing POAMs
✔✔What is the Information System Manager responsibilities? - ✔✔Provide daily
oversight of the operations of the information system
,Responsible for ensuring that configuration and change control processes are followed
Keep the ISSO informed about all decisions
✔✔What are the areas for Adjusting System Categorization? - ✔✔Aggregation
Critical System Functionality
Extenuating Circumstances
Public Information Integrity
Critical Infrastructures and Key Resources
Trade Secrets
Overall information system impact
Privacy Information
Health/HIPAA
✔✔What is system registration? - ✔✔System Registration Declaration
-Existence of system
-Key characteristics of the system
-Security Implications for the org due to ongoing operation of the system
✔✔What is NIST SP 800-12 - ✔✔Guide to Protecting the Confidentiality of Personally
Identifiable Information provides guidelines for a risk-based approach to protecting the
confidentiality of PII
✔✔How should org categorize PII? - ✔✔-Org should identify all PII residing in their
environment
-Org should minimize the use, collection, and retention of PII to what is strictly
necessary to accomplish their business purpose and mission
-Org should categorize their PII by the PII confidentiality impact level
✔✔NIST SP 800-47 - Security Guide for Interconnecting Information Systems
Technology - ✔✔This publication offers specific guidance and security ground rules for
interconnections.
✔✔What are the four step of the interconnect process? - ✔✔Plan
Establish
Maintain
Disconnect
✔✔What does a Memorandum of Understanding/Agreement (MOU/A) document? -
✔✔The terms and conditions for sharing data and information resources in a secure
manner.
✔✔What is the function of the Interconnection Security Agreement (ISA)? - ✔✔It details
how the interconnection is established or maintained.
, ✔✔What is the purpose of Capital Planning and Investment Control (CPIC) - ✔✔To
ensure that all IT investments directly support and align with the organizations mission
and strategic goals, and that all IT investments support business needs, while
minimizing risk and maximizing returns.
✔✔What does CPIC decision process ensure? - ✔✔IT investment integrate
-Strategic planning
-Budgeting
-Procurement
-IT Management
✔✔What does Clinger-Cohen Act of 1996 require? - ✔✔The Clinger-Cohen Act of 1996,
which requires agencies to use a disciplined capital planning and investment control
(CPIC) process to acquire, use, maintain,and dispose of IT in alignment with the
agency's EA planning processes. OMB policy for the management of Federal
information resources is detailed in Circular A-130, Management of Federal Information
Resources
✔✔What happens in RMF 2 - Select Controls - ✔✔Common Control Identification
Security Control Selection
Monitoring Strategy
Security Plan Approval
✔✔What happens in RMF 3 - Implement Controls - ✔✔Security Control Implementation
Security Control Documentation
✔✔What is FIPS 199 - ✔✔Standard for Security Categorization of Federal and
Information System
✔✔What is FIPS 200 - ✔✔Minimum Security Requirements for Federal Information and
Information Systems.
✔✔Baselines are based upon the IMPACT level as defined in FIPS 199, selected via
CNSSI-1253 or FIPS 200, and now implemented through catalog of controls found in
SP 800-53 - ✔✔True or False
True
✔✔Common Controls - ✔✔Inheritable
Org-wide exercise
Common control candidates
-Contingency planning
-Incident response
-Security training and awareness
-Personnel security
WITH ANSWERS RATED A+
✔✔What does Tier 3 address? - ✔✔Tier 3 addresses risk from an information system
perspective and is guided by the risk decisions at Tiers 1 and Tier 2
✔✔What NIST SPs cover Security Architeture - ✔✔SP-800-14, SP-800-27 and SP-800-
160
✔✔What are the four component of RMF - ✔✔Frame (risk)
Assess (risk)
Respond (to risk one determied)
Monitor (risk on an ongoing basis)
✔✔Which two NIST SP provide management overview and risk assessment guidance
on risk management? - ✔✔SP-800-37R1 - Guide to Applying the Risk Management
Framework to Federal Information Systems
SP-800-39 - Managing Information Security Risk (superseded SP-800-30
✔✔What is the CIO responsibilities (government personnel only) - ✔✔Designating
Senior Information Security Officer
Information Security Policies
Ensuring Adequately trained personnel
Assisting Senior Official with their security responsibilities
Appropriate Allocation of Resources
FISMA Reporting
✔✔What is the Risk Executive (function) (government personnel only) - ✔✔Ensure risk-
related considerations are organization wide
Consistent throughout organization
Coordinates with Senior Leadership
-Provide comprehensive approach
-Develop a Risk Management Strategy
-Facilitate sharing of risk information
-Provide oversight
-Provide forum to consider all risk sources
✔✔What is the Common Control Provider responsibilities? - ✔✔Documenting common
controls
Validating Required Control Assessments
Documenting assessment findings in SAR
Producing POAMs
✔✔What is the Information System Manager responsibilities? - ✔✔Provide daily
oversight of the operations of the information system
,Responsible for ensuring that configuration and change control processes are followed
Keep the ISSO informed about all decisions
✔✔What are the areas for Adjusting System Categorization? - ✔✔Aggregation
Critical System Functionality
Extenuating Circumstances
Public Information Integrity
Critical Infrastructures and Key Resources
Trade Secrets
Overall information system impact
Privacy Information
Health/HIPAA
✔✔What is system registration? - ✔✔System Registration Declaration
-Existence of system
-Key characteristics of the system
-Security Implications for the org due to ongoing operation of the system
✔✔What is NIST SP 800-12 - ✔✔Guide to Protecting the Confidentiality of Personally
Identifiable Information provides guidelines for a risk-based approach to protecting the
confidentiality of PII
✔✔How should org categorize PII? - ✔✔-Org should identify all PII residing in their
environment
-Org should minimize the use, collection, and retention of PII to what is strictly
necessary to accomplish their business purpose and mission
-Org should categorize their PII by the PII confidentiality impact level
✔✔NIST SP 800-47 - Security Guide for Interconnecting Information Systems
Technology - ✔✔This publication offers specific guidance and security ground rules for
interconnections.
✔✔What are the four step of the interconnect process? - ✔✔Plan
Establish
Maintain
Disconnect
✔✔What does a Memorandum of Understanding/Agreement (MOU/A) document? -
✔✔The terms and conditions for sharing data and information resources in a secure
manner.
✔✔What is the function of the Interconnection Security Agreement (ISA)? - ✔✔It details
how the interconnection is established or maintained.
, ✔✔What is the purpose of Capital Planning and Investment Control (CPIC) - ✔✔To
ensure that all IT investments directly support and align with the organizations mission
and strategic goals, and that all IT investments support business needs, while
minimizing risk and maximizing returns.
✔✔What does CPIC decision process ensure? - ✔✔IT investment integrate
-Strategic planning
-Budgeting
-Procurement
-IT Management
✔✔What does Clinger-Cohen Act of 1996 require? - ✔✔The Clinger-Cohen Act of 1996,
which requires agencies to use a disciplined capital planning and investment control
(CPIC) process to acquire, use, maintain,and dispose of IT in alignment with the
agency's EA planning processes. OMB policy for the management of Federal
information resources is detailed in Circular A-130, Management of Federal Information
Resources
✔✔What happens in RMF 2 - Select Controls - ✔✔Common Control Identification
Security Control Selection
Monitoring Strategy
Security Plan Approval
✔✔What happens in RMF 3 - Implement Controls - ✔✔Security Control Implementation
Security Control Documentation
✔✔What is FIPS 199 - ✔✔Standard for Security Categorization of Federal and
Information System
✔✔What is FIPS 200 - ✔✔Minimum Security Requirements for Federal Information and
Information Systems.
✔✔Baselines are based upon the IMPACT level as defined in FIPS 199, selected via
CNSSI-1253 or FIPS 200, and now implemented through catalog of controls found in
SP 800-53 - ✔✔True or False
True
✔✔Common Controls - ✔✔Inheritable
Org-wide exercise
Common control candidates
-Contingency planning
-Incident response
-Security training and awareness
-Personnel security