New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 ISSEP Exam - Topic 2 Question 1 Discussion

Actual exam question for ISC2's ISSEP exam
Question #: 1
Topic #: 2
[All ISSEP Questions]

Which of the following guidelines is recommended for engineering, protecting, managing, processing, and controlling national security and sensitive (although unclassified) information?

Show Suggested Answer Hide Answer
Suggested Answer: B

The Special Publication (SP) is the guideline that is recommended for engineering, protecting, managing, processing, and controlling national security and sensitive (although unclassified) information. Answer option D is incorrect. The Department of Defense Information Assurance

Certification and Accreditation Process (DIACAP) is a process defined by the United States

Department of Defense (DoD) for managing risk. DIACAP replaced the former process, known as

DITSCAP (Department of Defense Information Technology Security Certification and Accreditation

Process), in 2006. DoD Instruction (DoDI) 8510.01 establishes a standard DoD-wide process with a

set of activities, general tasks, and a management structure to certify and accredit an Automated

Information System (AIS) that will maintain the Information Assurance (IA) posture of the Defense

Information Infrastructure (DII) throughout the system's life cycle. The DIACAP process is different

from DITSCAP or NIACAP. Its overall process is similar to other C&A activities. The DIACAP process

consists of five phases, which are as follows:

1.Initiate and Plan IA C&A. This phase consists of the following activities:

Register system with DoD Component IA Program.

Assign IA controls.

Assemble DIACAP team.

Develop DIACAP strategy.

Initiate IA implementation plan.

2.Implement and Validate Assigned IA Controls: This phase consists of the following activities:

Execute and update IA implementation plan. Conduct validation activities. Combine validation

results in DIACAP scorecard. 3.Make Certification Determination and Accreditation Decisions: This

phase consists of the following activities:

Analyze residual risk.Issue certification determination.Make accreditation decision.

4.Maintain Authority to Operate and Conduct Reviews: This phase consists of the following activities:

Initiate and update lifecycle implementation plan for IA controls.

Maintain situational awareness.Maintain IA posture.

5.Decommission System: This phase consists of the following activities:

Conduct activities related to the disposition of the system data and objects.

Answer option A is incorrect. FIPS emphasizes on design, implementation, and approval of

cryptographic algorithms.Answer option C is incorrect. NISTIRs (Internal Reports) illustrate the study of a technical nature of interest to focused audience. NISTIRs consist of interim or final reports on work made by NIST for external sponsors, including government and non-government sponsors.


Contribute your Thoughts:

0/2000 characters
Sherly
4 months ago
Really? I didn't know FIPS was that important for unclassified info!
upvoted 0 times
...
Leanna
4 months ago
SPs are super useful too, but not as comprehensive as FIPS.
upvoted 0 times
...
Leatha
4 months ago
I thought DIACAP was more for military-specific guidelines?
upvoted 0 times
...
Georgene
4 months ago
Totally agree, FIPS covers a lot of ground!
upvoted 0 times
...
Luisa
5 months ago
FIPS is the way to go for federal info standards.
upvoted 0 times
...
Theola
5 months ago
DIACAP seems more focused on military applications, so I doubt it's the answer here. I think it might be one of the other options.
upvoted 0 times
...
Fidelia
5 months ago
I remember practicing questions about NISTIRs, but I can't remember if they were the right choice for this context.
upvoted 0 times
...
Reyes
5 months ago
I feel like we covered FIPS in class, but I can't recall if it specifically applies to unclassified information.
upvoted 0 times
...
Malissa
5 months ago
I think it might be Special Publication (SP), but I'm not entirely sure. I remember it being related to guidelines for sensitive information.
upvoted 0 times
...
Erinn
5 months ago
I'm not sure about the Script Task, so I might try option C and remove it to see if that fixes the issue.
upvoted 0 times
...
Kimberely
5 months ago
Okay, let me think this through. I know one way is manually by a moderator, but I'm not sure about the other option. I'll have to carefully read through the choices.
upvoted 0 times
...
Dorthy
5 months ago
I'm leaning towards B because of how it includes digits, but that doesn't feel right for first names, right? I need to double-check!
upvoted 0 times
...
Anna
5 months ago
Okay, I've got this. Consequences are always negative when it comes to safety, so the answer has to be A.
upvoted 0 times
...

Save Cancel