Federal Compliance and Regulatory Requirements Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Federal Compliance and Regulatory Requirements flashcards as text
Under FISMA, what annual requirement must federal agencies fulfill regarding their information security programs?
Answer: Submit an annual report to OMB and Congress on their security program status
FISMA requires federal agencies to report annually to OMB and Congress on the effectiveness of their information security programs.
Which body conducts independent audits of federal agency information security programs and reports findings to Congress?
Answer: GAO (Government Accountability Office)
The GAO conducts independent audits and evaluations of federal programs, including information security, and reports to Congress.
What does NIST SP 800-60 help federal agencies determine?
Answer: Which information types and systems belong in which FIPS 199 impact categories
NIST SP 800-60 maps information types to security impact levels, guiding agencies in applying FIPS 199 categorization consistently.
Which federal policy requires agencies to report major cybersecurity incidents to CISA and Congress within a specific timeframe?
Answer: FISMA 2014 and OMB reporting requirements
FISMA 2014 and related OMB memoranda require agencies to report major incidents to CISA and notify Congress within prescribed timeframes.
The National Cybersecurity Strategy released in 2023 by the Biden administration emphasized shifting cybersecurity responsibility to whom?
Answer: Technology providers and organizations best positioned to reduce risk
The 2023 National Cybersecurity Strategy called for shifting the cybersecurity burden from individuals to technology vendors and large organizations.
Executive Order 14028, issued in May 2021, directed federal agencies to take which key action?
Answer: Improve the nation's cybersecurity through software supply chain security, zero trust, and enhanced incident reporting
EO 14028 required federal agencies to modernize cybersecurity by adopting zero trust, improving software supply chain security, and enhancing incident logging.