2. Crucial Publications and Laws Flashcards

1
Q

CNSS 1253a

“Security Categorization and Control Selection for National Security Systems”

A

Provides all Federal Government departments, agencies, etc. with guidance on the first two steps of the RMF (Categorize and Select) for National Security Systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

FIPS 199

A

Develop standards for categorizing information and information systems.

Security categorization standards for information and information systems provide a common framework and understanding for expressing security (Low, Med, High)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

FIPS 200

A

Addresses specification of minimum security requirements for federal information and information systems.

Minimum security requirements cover 17 areas to protect the C-I-A of federal information systems and their information.

  1. access control
  2. awareness, training
  3. audit, accountability
  4. certification, accreditation, assessments
  5. configuration management
  6. contingency planning
  7. identification, authentication
  8. incident response
  9. maintenance
  10. media protection
  11. physical, environmental protection
  12. planning
  13. personnel security
  14. risk assessment
  15. systems and services acquisition
  16. system and communications protection
  17. system and information integrity
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

SP 800-30

Guide for Conducting Risk Assessments

A

Guidance for conducting risk assessments

Amplifies guidance in SP 800-39.

Risk assessments cat all 3 tiers of the risk management hierarchy are part of an overall risk management process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

SP 800-37

Risk Management Framework

A

Core publication describing the RMF in detail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SP 800-39

Managing Information Security Risk

A

Guidance for integrated, organization-wide program for managing information security risk to organizational operations (ie mission, functions, image, reputation), assets, individuals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SP 800-53

Security and Privacy Controls for Federal Information Systems

A

Guidelines for selecting and specifying security controls to meet requirements of FIPS 200

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SP 800-60

Guide for Mapping Types of Information and IS to Security Categories

A

Maps information types to FIPS 199

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

SP 800-64

Security Considerations in the System Development Lifecycle

A

Assists in integrating essential IT security steps into established IT System Development Lifecycle

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

SP 800-137

Information Security Continuous Monitoring

A

Maintaining ongoing awareness of information security, vulnerabilities and threats to support risk management decisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Section 3541 Title 44 USC

A

Federal Information Security Management Act 2002

FISMA compels government to secure its IT resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

OMB Circular A-130

A

Establishes minimum set of controls to be included in Federal infosec programs.

Assigns federal agency responsibilities for the security of automated information

Links agency automated infosec programs and agency management control systems established IAW OMB A-123

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

OMB Circular A-123

A

Guidance to federal managers on improving accountability and effectiveness of Federal programs by establishing, assessing, correcting, reporting on internal control.

Attachment this circular defines management responsibilities for internal control and the process for assessing internal control effectiveness, with a summary of the major changes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

USC 552a

A

Privacy Act of 1974

Establishes code of fair information practices that govern collection, maintenance, use and dissemination of information about individuals that is maintained in federal systems of records.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

FISMA

A

Agencies must engage in authorization per OMB A-130

Agencies must maintain an information systems inventory

Agencies must categorize their information systems per FIPS 199 and SP 800-60

Agencies must meet minimum requirements by implementing and assessing security controls per FIPS 200 and SP 800-53
(800-53 references 800-37 so it is also compulsory with other SPs, but agencies have attitude for how to be compliant)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Adequate Security

OMB Circular A-130

A

Security commensurate with the risk and magnitude of harm resulting from loss, misuse or unauthorized access to or modification of information

This includes assuring systems and applications used, operate effectively and appropriately protect the CIA