CAP Federal Compliance and Regulatory Requirements 1 — Questions and Answers
Question 1: Which federal law established the modern framework for federal information security and was significantly updated in 2014?
- Privacy Act of 1974
- Clinger-Cohen Act of 1996
- Federal Information Security Modernization Act (FISMA) (Correct answer)
- Sarbanes-Oxley Act
Correct answer: Federal Information Security Modernization Act (FISMA)
FISMA 2014 updated the original 2002 law to strengthen DHS's role, require automated monitoring, and improve incident reporting.
Question 2: Which federal agency is responsible for issuing FIPS publications that federal agencies must comply with?
- NSA
- CISA
- NIST (Correct answer)
- OMB
Correct answer: NIST
The National Institute of Standards and Technology (NIST) issues Federal Information Processing Standards (FIPS) publications.
Question 3: OMB Circular A-130 provides federal policy guidance on which broad area?
- Federal procurement rules
- Managing federal information resources, including IT security and privacy (Correct answer)
- Congressional budget procedures
- Federal hiring standards
Correct answer: Managing federal information resources, including IT security and privacy
OMB Circular A-130 establishes federal policy for managing information resources, including requirements for information security and privacy.
Question 4: Which federal privacy law gives US citizens the right to access and correct records held by federal agencies?
- HIPAA
- FERPA
- Privacy Act of 1974 (Correct answer)
- COPPA
Correct answer: Privacy Act of 1974
The Privacy Act of 1974 governs federal agency collection, maintenance, use, and dissemination of personally identifiable information.
Question 5: Executive Order 13800 directed federal agencies to take what primary action regarding cybersecurity risk?
- Adopt zero-trust architecture immediately
- Use the NIST Cybersecurity Framework to manage institutional risk (Correct answer)
- Transfer all systems to commercial cloud
- Eliminate all legacy systems within one year
Correct answer: Use the NIST Cybersecurity Framework to manage institutional risk
EO 13800 required agency heads to use the NIST Cybersecurity Framework to manage cybersecurity risk as part of enterprise risk management.
Question 6: Under FISMA, which office provides policy guidance and oversight for federal information security programs?
- NSA
- CISA
- OMB (Correct answer)
- GAO
Correct answer: OMB
The Office of Management and Budget (OMB) issues policy guidance and oversees federal agency compliance with FISMA requirements.
Which federal law established the modern framework for federal information security and was significantly updated in 2014?