Which statement best describes the significance of the Federal Information Security Modernization Act of 2014 (FISMA)?

Study for the EC-Council Certified Ethical Hacker (CEH) v13 Exam. Utilize flashcards and multiple-choice questions with helpful hints and detailed explanations. Excel in your exam preparation!

Multiple Choice

Which statement best describes the significance of the Federal Information Security Modernization Act of 2014 (FISMA)?

Explanation:
FISMA 2014 is about making sure federal agencies protect their information and information systems and do so using the standards and guidelines developed by NIST. The law strengthens the obligation for agencies to manage security risk through formal programs, ongoing monitoring, and regular assessments, all aligned with NIST guidelines such as the security controls and the risk management framework. That combination—mandatory protection of information/assets plus reliance on NIST standards—best captures the act’s purpose. This isn’t about private sector encryption standards, nor does it extend to defining risk management for state governments, and it doesn’t specifically lay out authentication methods for personal devices. The emphasis is on federal agencies securing information systems using NIST as the baseline.

FISMA 2014 is about making sure federal agencies protect their information and information systems and do so using the standards and guidelines developed by NIST. The law strengthens the obligation for agencies to manage security risk through formal programs, ongoing monitoring, and regular assessments, all aligned with NIST guidelines such as the security controls and the risk management framework. That combination—mandatory protection of information/assets plus reliance on NIST standards—best captures the act’s purpose.

This isn’t about private sector encryption standards, nor does it extend to defining risk management for state governments, and it doesn’t specifically lay out authentication methods for personal devices. The emphasis is on federal agencies securing information systems using NIST as the baseline.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy