Filters
Question type

Study Flashcards

The federal government prohibits the distribution of best security practices with organizations other than federal agencies._________________________

A) True
B) False

Correct Answer

verifed

verified

Which of the following is NOT a goal of the NIST System Certification and Accreditation Project:


A) Develop standard guidelines and procedures for certifying and accrediting corporate IT systems, including the critical infrastructure of the United States
B) Define essential minimum security controls for federal IT systems
C) Promote the development of public- and private-sector assessment organizations and certification of individuals capable of providing cost-effective, high-quality security certifications based on standard guidelines and procedures
D) All of these are goals of the NIST C&A Project

E) B) and D)
F) A) and B)

Correct Answer

verifed

verified

NIST recommends the documentation of each performance measure in a customized format to ensure repeatability of measures development,tailoring,collection,and reporting activities.

A) True
B) False

Correct Answer

verifed

verified

It is no longer sufficient to simply assert effective information security; an organization must demonstrate that it is taking effective measures in the spirit of due diligence._________________________

A) True
B) False

Correct Answer

verifed

verified

In the future,NIST is replacing traditional Certification and Accreditation with authorization strategies and security control assessment.

A) True
B) False

Correct Answer

verifed

verified

Certification is defined as "the comprehensive evaluation of the technical and nontechnical security controls of an IT system to support the accreditation process that establishes the extent to which a particular design and implementation meets a set of specified security requirements.

A) True
B) False

Correct Answer

verifed

verified

A(n)baseline is a "value or profile of a performance metric against which changes in the performance metric can be usefully compared." _________________________

A) True
B) False

Correct Answer

verifed

verified

The process of implementing a performance measures program recommended by NIST involves six phases.List them.

Correct Answer

verifed

verified

Phase 1: Prepare for data collection; id...

View Answer

Organizations typically use three types of performance measures,including those that assess the impact of a(n)____________________ or other security event on the organization or its mission.

Correct Answer

verifed

verified

During Phase 1 of the NIST performance measures development process,the organization identifies relevant ____ and their interests in information security measurement.


A) stakeholders
B) users
C) goals and objectives
D) regulations

E) B) and D)
F) A) and B)

Correct Answer

verifed

verified

By looking at the paths taken by organizations similar to the one whose plan you are developing,known as benchmarking,the organization can follow the recommended or existing practices of a similar organization or industry-developed standards._________________________

A) True
B) False

Correct Answer

verifed

verified

Production level statistics depend greatly on the number of systems and the number of users of those systems._________________________

A) True
B) False

Correct Answer

verifed

verified

Implementing controls at an acceptable standard-and maintaining them-demonstrates that an organization has performed due diligence._________________________

A) True
B) False

Correct Answer

verifed

verified

Best security practices (BSPs)balance the need for information access with the need for adequate protection while simultaneously demonstrating social responsibility.

A) True
B) False

Correct Answer

verifed

verified

In future certification and accreditation practices,NIST will focus less on certification and accreditation strategies,and more on ____.


A) holistic risk management strategy
B) accreditation and certification
C) managed controls
D) international standards such as ISO

E) A) and D)
F) A) and C)

Correct Answer

verifed

verified

The ____________________ standard is a model level of performance that demonstrates industrial leadership,quality,and concern for the protection of information.

Correct Answer

verifed

verified

The benefits of using information security performance measures include "increasing ____________________ for information security performance; improving effectiveness of information security activities; demonstrating compliance with laws,rules,and regulations; and providing quantifiable inputs for resource allocation decisions."

Correct Answer

verifed

verified

One of the critical tasks in the measurement process is to assess and ____________________ what will be measured.

Correct Answer

verifed

verified

The ____ standard is a model level of performance that demonstrates industrial leadership,quality,and concern for the protection of information.


A) Silver
B) Gold
C) Platinum
D) Diamond

E) All of the above
F) A) and D)

Correct Answer

verifed

verified

Good security now is better ____.


A) than nothing
B) than a kick in the teeth
C) than perfect security never
D) delayed until better security can be developed

E) All of the above
F) A) and B)

Correct Answer

verifed

verified

Showing 41 - 60 of 114

Related Exams

Show Answer