50.3k views
5 votes
In order to develop the system security plan, it is necessary to be familiar with FIPS _______, FIPS _________, NIST SP 800-_________, NIST SP 800-_________, and NIST SP 800-_________.

A) FIPS 199, FIPS 200, NIST SP 800-37, NIST SP 800-53, NIST SP 800-137
B) FIPS 202, FIPS 204, NIST SP 800-64, NIST SP 800-171, NIST SP 800-55
C) FIPS 140-2, FIPS 140-3, NIST SP 800-66, NIST SP 800-82, NIST SP 800-171
D) FIPS 197, FIPS 201, NIST SP 800-30, NIST SP 800-61, NIST SP 800-98

1 Answer

5 votes

Final answer:

To develop a system security plan, familiarity with FIPS 199, FIPS 200, and NIST SP 800 series publications including 800-37, 800-53, and 800-137 is necessary as they provide guidelines for security assessment and risk management.

Step-by-step explanation:

In order to develop a system security plan, it is indeed necessary to be familiar with certain Federal Information Processing Standards (FIPS) and National Institute of Standards and Technology Special Publications (NIST SPs). Specifically, one should know FIPS 199, FIPS 200, NIST SP 800-37, NIST SP 800-53, and NIST SP 800-137:

  • FIPS 199: Standards for Security Categorization of Federal Information and Information Systems
  • FIPS 200: Minimum Security Requirements for Federal Information and Information Systems
  • NIST SP 800-37: Guide for Applying the Risk Management Framework to Federal Information Systems
  • NIST SP 800-53: Security and Privacy Controls for Information Systems and Organizations
  • NIST SP 800-137: Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations

These documents provide a framework for assessing and managing cybersecurity risk, which is essential for developing comprehensive and effective system security plans.

User Kreshnik
by
8.6k points