Which SP is described as a guide for developing security plans for federal information systems?

Prepare for the FISMA Interview Test. Get familiar with key topics and enhance your knowledge with flashcards and multiple-choice questions. Study effectively and be ready for your exam!

Multiple Choice

Which SP is described as a guide for developing security plans for federal information systems?

Explanation:
This question tests you on knowing which NIST publication specifically guides the creation of security plans for federal information systems. The best answer is NIST SP 800-18, which is titled Guide for Developing Security Plans for Federal Information Systems. This publication lays out how to prepare and maintain a System Security Plan (SSP) that describes the system, its boundary, the environment, the security controls in place, responsibilities, and how the plan ties into authorization and ongoing risk management. It’s the exact resource for developing security plans, which is why it’s the correct choice. The other publications cover different topics: one focuses on the overall Risk Management Framework and process, another on contingency planning, and another on mapping information types and security categories, not on the security plan itself.

This question tests you on knowing which NIST publication specifically guides the creation of security plans for federal information systems. The best answer is NIST SP 800-18, which is titled Guide for Developing Security Plans for Federal Information Systems. This publication lays out how to prepare and maintain a System Security Plan (SSP) that describes the system, its boundary, the environment, the security controls in place, responsibilities, and how the plan ties into authorization and ongoing risk management. It’s the exact resource for developing security plans, which is why it’s the correct choice. The other publications cover different topics: one focuses on the overall Risk Management Framework and process, another on contingency planning, and another on mapping information types and security categories, not on the security plan itself.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy