← All CAP Flashcard Decks

Federal Information Security Laws, Policies & the Legislative Framework Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Federal Information Security Laws, Policies & the Legislative Framework flashcards as text
  1. Which U.S. federal law established the requirement for federal agencies to develop, document, and implement an information security program, and made NIST responsible for developing security standards and guidelines?

    Answer: The Federal Information Security Management Act (FISMA) of 2002

    FISMA 2002 (part of the E-Government Act) is the foundational federal law requiring agencies to implement agency-wide information security programs. It mandated NIST to develop standards (FIPS) and guidelines (SP 800-series) for federal information security.

  2. The Federal Information Security Modernization Act (FISMA) of 2014 made which significant change to the original 2002 law?

    Answer: It shifted FISMA oversight from OMB to DHS for operational civilian agency oversight, and emphasized continuous monitoring over periodic assessments.

    FISMA 2014 modernized the 2002 law by giving DHS a more active role in operational oversight of civilian agencies (while OMB retained policy authority), strengthening continuous monitoring requirements, and increasing incident reporting obligations — reflecting the shift away from compliance-driven point-in-time assessments.

  3. OMB Circular A-130 is significant to the CAP domain because it:

    Answer: Sets policy for managing federal information resources and requires agencies to implement NIST-based security controls.

    OMB Circular A-130 ('Managing Information as a Strategic Resource') establishes government-wide policy for the management of federal information resources, including a requirement to implement security controls consistent with NIST standards. It is the policy backbone that makes the RMF mandatory for federal civilian agencies.

  4. Under FISMA, which official has the authority to grant an Authorization to Operate (ATO) for a federal information system?

    Answer: The Authorizing Official (AO), also known as the Designated Accrediting Authority (DAA)

    The Authorizing Official (AO) — historically called the Designated Accrediting Authority (DAA) — is the senior federal official with the authority and accountability to grant an ATO. The AO accepts the residual risk of operating a system based on the authorization package and current security posture.

  5. Which federal agency is responsible for developing mandatory standards (FIPS) and voluntary guidelines (SP 800-series) for federal information systems under FISMA?

    Answer: The National Institute of Standards and Technology (NIST)

    FISMA explicitly tasks NIST with developing FIPS (Federal Information Processing Standards, which are mandatory) and Special Publications in the 800-series (which are guidelines). DHS handles operational oversight; OMB handles policy; GAO audits compliance — but only NIST creates the technical standards.

  6. A federal contractor operating an information system that processes, stores, or transmits federal data on behalf of a federal agency is subject to FISMA requirements under which mechanism?

    Answer: The federal agency includes FISMA and NIST control requirements in the contract, making the contractor's system subject to the same security requirements.

    FISMA applies to federal agencies and extends to contractors through contractual requirements. Federal agencies must include information security requirements (aligned to NIST standards) in contracts with third-party providers who handle federal information, making those systems subject to the same RMF-based requirements as agency-owned systems.

Federal Information Security Laws, Policies & the Legislative Framework Flashcards — CAP Study Cards with Answers