Compliance and Auditing IT Compliance and Security 2 — Questions and Answers
Question 1: What is a 'system security plan' (SSP) required by FISMA?
- A disaster recovery plan for IT systems
- A formal document that provides an overview of security requirements and describes the controls in place (Correct answer)
- An incident response playbook
- A network architecture diagram
Correct answer: A formal document that provides an overview of security requirements and describes the controls in place
A System Security Plan (SSP) is a formal document required by FISMA that describes the system boundary, security requirements, and security controls implemented to protect a federal information system.
Question 2: Which process under NIST RMF involves selecting and implementing security controls?
- Categorize
- Select and Implement (Correct answer)
- Assess
- Authorize
Correct answer: Select and Implement
The NIST Risk Management Framework (RMF) Select step involves choosing appropriate security controls from NIST SP 800-53 based on the system's security categorization, and the Implement step involves putting those controls in place.
Question 3: What is a 'vulnerability scan' primarily used for in IT compliance?
- Monitoring employee internet usage
- Automatically identifying known security weaknesses in systems and software (Correct answer)
- Testing disaster recovery procedures
- Analyzing network traffic patterns
Correct answer: Automatically identifying known security weaknesses in systems and software
Vulnerability scanning uses automated tools to identify known security vulnerabilities, misconfigurations, and weaknesses in systems, applications, and network devices.
Question 4: What is 'patch management' as an IT compliance control?
- Managing software licensing agreements
- The systematic process of identifying, acquiring, testing, and deploying software updates to fix vulnerabilities (Correct answer)
- Patching physical damage to IT equipment
- Managing network configuration changes
Correct answer: The systematic process of identifying, acquiring, testing, and deploying software updates to fix vulnerabilities
Patch management is a systematic process for identifying security vulnerabilities in software and applying vendor-released patches in a timely manner to reduce the window of exposure to exploitation.
Question 5: In cybersecurity compliance, what is a 'Security Information and Event Management' (SIEM) system used for?
- Managing employee security awareness training
- Collecting and analyzing security event logs to detect threats and support compliance reporting (Correct answer)
- Encrypting sensitive data transmissions
- Managing digital certificates
Correct answer: Collecting and analyzing security event logs to detect threats and support compliance reporting
A SIEM system aggregates and analyzes security event logs from across the IT environment to detect suspicious activity, support incident response, and generate compliance reports.
Question 6: What is the purpose of a 'data loss prevention' (DLP) solution in compliance programs?
- Recovering deleted files from backups
- Detecting and preventing unauthorized transmission or exfiltration of sensitive data (Correct answer)
- Encrypting data stored in databases
- Managing data retention schedules
Correct answer: Detecting and preventing unauthorized transmission or exfiltration of sensitive data
Data Loss Prevention (DLP) solutions monitor and control data movement to prevent unauthorized transmission of sensitive data outside the organization, supporting compliance with regulations like HIPAA and PCI DSS.
What is a 'system security plan' (SSP) required by FISMA?