Reference no: EM133225874
Question: Name the NIST publication that provides guidance on control assessment and indicates the controls for which interview, document examination and configuration testing (EIT testing procedures) may be performed
Which of the technical, operational or management control class requires most Test (i.e, review of system configuration screenshot/report) as assessment method based on NIST 800-53A security controls assessment/testing guide?
Name the document that contains the security assessment planning activities for A&A project
When is e-authentication assessment and documentation required for a system?
Does e-authentication assurance level 3 require a single-factor or multi-factor authentication?
When is privacy impact assessment (PIA) required for a system?
What is the full meaning of SORN, where is it published and name one of the conditions that requires its being created
For how long is a control waiver typically approved?
What are the two reasons why an exception may be approved for a finding?
Name the NIST publication that provides guidance for risk assessment, and used for determining risk level of identified security control findings
What is an SSP
What is RTM
What is PTA and when is it used
Name all the documents or packages that must be completed in order to get an ATO
What is SAP and when is it used
What is a Rule of Engagement
Clearly discuss in your own words the assessment step in RMF
You are hired at the Department of Agriculture to conduct an assessment by meeting with the system owner. Using NIST 800 53A ref 4, using interviewing method, complete this interview by asking question using this controls: AU-3, CM-6, AT 3, CM7 and CM-3
In your own words clearly describe the use of NIST 800 60 and NIST 800 18.
What is the meaning of DRP, PII, CP, CM