CSPM Security Industry-Specific Knowledge 2 — Questions and Answers
Question 1: Under NIST SP 800-37, which step in the Risk Management Framework (RMF) involves defining the system boundary and the types of information processed?
- Assess
- Categorize (Correct answer)
- Implement
- Authorize
Correct answer: Categorize
The Categorize step establishes the system boundary and classifies information based on impact levels using FIPS 199 criteria.
Question 2: A physical security project must comply with PACS (Physical Access Control System) integration requirements. Which standard governs interoperability between PACS and government identity credentials?
- ISO 27001
- FIPS 201 / PIV (Correct answer)
- NIST 800-53
- ANSI/ASIS PSC.1
Correct answer: FIPS 201 / PIV
FIPS 201 establishes the Personal Identity Verification (PIV) standard that PACS must support to accept government-issued credentials.
Question 3: Which document type is used to formally record acceptance of residual risk by an authorizing official in a government security program?
- System Security Plan (SSP)
- Plan of Action and Milestones (POA&M)
- Authorization to Operate (ATO) (Correct answer)
- Security Assessment Report (SAR)
Correct answer: Authorization to Operate (ATO)
An ATO is issued by the authorizing official to formally accept residual risk and permit the system to operate.
Question 4: In the context of supply chain security, what does the term 'counterfeit electronic part' most directly threaten in a security project?
- Budget overruns due to replacement costs
- System integrity and mission assurance (Correct answer)
- Schedule delays due to vendor audits
- Regulatory fines under ITAR
Correct answer: System integrity and mission assurance
Counterfeit parts can introduce hidden vulnerabilities or fail prematurely, directly threatening system integrity and mission assurance.
Question 5: A security manager is reviewing a contract for a guard force provider. Which labor regulation most directly governs wage and benefit requirements for private security officers on federal contracts?
- Davis-Bacon Act
- Service Contract Act (SCA) (Correct answer)
- Fair Labor Standards Act (FLSA)
- Walsh-Healey Public Contracts Act
Correct answer: Service Contract Act (SCA)
The Service Contract Act sets minimum wage, fringe benefit, and working condition requirements for employees on federal service contracts, including guard services.
Question 6: Which ASIS standard provides guidance specifically for the management of workplace violence prevention programs?
- ASIS SPC.1
- ASIS/SHRM WVPI.1 (Correct answer)
- ASIS PSC.1
- ASIS ORM.1
Correct answer: ASIS/SHRM WVPI.1
ASIS/SHRM WVPI.1 is the Workplace Violence Prevention and Intervention standard developed jointly by ASIS and the Society for Human Resource Management.
Question 7: When conducting a threat assessment for a critical infrastructure facility, which DHS tool provides a structured methodology for identifying and prioritizing security gaps?
- CARVER Matrix
- SVA (Security Vulnerability Assessment) Methodology (Correct answer)
- OCTAVE Allegro
- FEMA THIRA
Correct answer: SVA (Security Vulnerability Assessment) Methodology
DHS's Security Vulnerability Assessment (SVA) methodology provides a structured, sector-specific framework for identifying gaps in critical infrastructure protection.
Under NIST SP 800-37, which step in the Risk Management Framework (RMF) involves defining the system boundary and the types of information processed?