CAP Federal Compliance and Regulatory Requirements 2 — Questions and Answers
Question 1: Which regulation governs the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems?
- NIST SP 800-53
- NIST SP 800-171 (Correct answer)
- FIPS 199
- OMB M-17-12
Correct answer: NIST SP 800-171
NIST SP 800-171 establishes requirements for protecting CUI in nonfederal systems and organizations, particularly for DoD contractors.
Question 2: What does the term 'Controlled Unclassified Information' (CUI) refer to?
- Top Secret/SCI data
- Information the government requires safeguarding per law, regulation, or policy, but is not classified (Correct answer)
- Publicly releasable federal records
- Classified defense information
Correct answer: Information the government requires safeguarding per law, regulation, or policy, but is not classified
CUI is sensitive government information that requires protection but does not meet the threshold for national security classification.
Question 3: Which federal law requires agencies to conduct Privacy Impact Assessments for new information technology systems?
- FISMA
- Privacy Act of 1974
- E-Government Act of 2002 (Correct answer)
- Federal Records Act
Correct answer: E-Government Act of 2002
Section 208 of the E-Government Act of 2002 mandates PIAs before agencies develop or procure new IT systems that collect PII.
Question 4: CISA plays which primary role in federal cybersecurity compliance?
- Issues FIPS publications
- Coordinates federal civilian cybersecurity defense and leads incident response (Correct answer)
- Approves agency ATOs
- Audits agency compliance with FISMA
Correct answer: Coordinates federal civilian cybersecurity defense and leads incident response
CISA (Cybersecurity and Infrastructure Security Agency) leads the national effort to defend civilian federal networks and coordinate incident response.
Question 5: The Federal Risk and Authorization Management Program (FedRAMP) standardizes security authorizations for which type of systems?
- On-premises legacy systems
- Cloud computing products and services used by federal agencies (Correct answer)
- Classified national security systems
- Mobile device management platforms
Correct answer: Cloud computing products and services used by federal agencies
FedRAMP provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by the federal government.
Question 6: Which OMB memorandum introduced the 'Assume Breach' mentality and required agencies to adopt zero trust architecture?
- OMB M-21-31
- OMB M-22-09 (Correct answer)
- OMB M-17-12
- OMB A-130
Correct answer: OMB M-22-09
OMB M-22-09 established a federal zero trust architecture strategy requiring agencies to meet specific zero trust security goals.
Which regulation governs the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems?