IS3350 CHAPTER 8 Flashcards
A federal government official who independently evaluates the performance of federal agencies. These are independent officials and called ___?
INSPECTOR GENERAL
Information technology systems that hold military, defense, and intelligence information is called ___?
NATIONAL SECURITY SYSTEMS
A review of how a federal agency’s IT systems process personal information. The E-Government Act of 2002 requires Federal agencies to conduct these assessments and is called ___?
PRIVACY IMPACT ASSESSMENT (PIA)
Any information about a person that a federal agency maintains. This term is also defined by the Privacy Act of 1974 and is called a ___?
RECORD
A federal agency’s notice about agency record-keeping systems that can retrieve records through the use of a personal identifies. The Privacy Act of 1974 requires federal agencies to provide these notices. This is called ___?
SYSTEM OF RECORDS NOTICE (SORN)
- Which regulation controls the export of military or defense applications and technology?
- ITAR
- EAR
- OFAC
- FDIC
- none of the above
ITAR
- What information must a federal agency include in a privacy impact assessment?
State what information is to be collected;
Why the information is being collected;
The intended use of the information;
How the agency will share the information;
Whether people have the opportunity to consent to specific uses of the info;
How the information will be secured;
Whether the info collected will be a system of records as defined by the Privacy Act of 1974
- The information collected in a PIA and a SORN is based upon what principles?
- NIST standards
- OMB standards
- Fair information privacy practices
- OTAR regulations
- None of the above
Fair information privacy practices
- Which assessment must be completed any time a federal agency collects personal information that can be retrieved via a personal identifier?
- PIA
- SORN
- ACORN
- OFAC
- None of the above
SORN
- Which agency has primary oversight responsibilities under FISMA?
- DoD
- CIA
- NIST
- CNSS
- None of the above
None of the above
- Federal agencies must report information security incidents to ____?
US-CERT
- Federal agencies must test their information security controls every six months.
TRUE OR FALSE
FALSE
- What are federal information security challenges?
- A culture of merely complying with reporting requirement
- Lack of an enterprise approach
- Lack of coordination within the federal government
- All the above
- None of the above
- A culture of merely complying with reporting requirement
- Lack of an enterprise approach
- Lack of coordination within the federal government
ALL THE ABOVE
- What is the name of the FISMA data-collection tool?
CyberScope
- Which type of NIST guidance follows a formal creation process?
- Special Publications
- Federal Information Processing Standards
- Guidelines for Information Security
- Fair information practice principles
- None of the above
Federal Information Processing Standards