Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 Exam ISSEP Topic 5 Question 67 Discussion

Actual exam question for ISC2's ISSEP exam
Question #: 67
Topic #: 5
[All ISSEP Questions]

The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems that handle U.S. national security information. Which of the following participants are required in a NIACAP security assessment Each correct answer represents a part of the solution. Choose all that apply.

Show Suggested Answer Hide Answer
Suggested Answer: A, B, D

Following are the different types of policies:

Regulatory: This type of policy ensures that the organization is following standards set by specific

industry regulations. This policy type

is very detailed and specific to a type of industry. This is used in financial institutions, health care

facilities, public utilities, and other

government-regulated industries, e.g., TRAI.

Advisory: This type of policy strongly advises employees regarding which types of behaviors and

activities should and should not take

place within the organization. It also outlines possible ramifications if employees do not comply with

the established behaviors and

activities. This policy type can be used, for example, to describe how to handle medical information,

handle financial transactions, or

process confidential information.

Informative: This type of policy informs employees of certain topics. It is not an enforceable policy,

but rather one to teach individuals

about specific issues relevant to the company. It could explain how the company interacts with

partners, the company's goals and

mission, and a general reporting structure in different situations.

Answer option C is incorrect. No such type of policy exists.


Contribute your Thoughts:

Jeffrey
9 days ago
Hmm, the IS program manager and user representative - those make sense as well. Can't leave out the folks who actually use the system!
upvoted 0 times
...
Gennie
10 days ago
I'm not sure about E, the User representative. I think it might not be required for a NIACAP security assessment.
upvoted 0 times
...
Luis
17 days ago
The Information Assurance Manager and Certification Agent seem like obvious choices too. Gotta have those experts involved, right?
upvoted 0 times
Brittani
2 days ago
A) Information Assurance Manager
upvoted 0 times
...
...
Maybelle
18 days ago
I'm pretty sure the Designated Approving Authority is a key participant in the NIACAP security assessment. Can't forget about that one!
upvoted 0 times
...
Tabetha
19 days ago
I agree with Tawna. A, B, C, and D make sense because they all play important roles in the certification and accreditation process.
upvoted 0 times
...
Tawna
25 days ago
I think A, B, C, and D are required in a NIACAP security assessment.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77