New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 ISSEP Exam - Topic 5 Question 53 Discussion

Actual exam question for ISC2's ISSEP exam
Question #: 53
Topic #: 5
[All ISSEP Questions]

Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct answer represents a part of the solution. Choose all that apply.

Show Suggested Answer Hide Answer
Suggested Answer: A, C

FISMA and Office of Management and Budget (OMB) require all general support systems and major

applications to be fully certified and

accredited before they are put into production. General support systems and major applications are

also referred to as information systems

and are required to be reaccredited every three years.

Answer option B is incorrect. The National Institute of Standards and Technology (NIST), known

between 1901 and 1988 as the National

Bureau of Standards (NBS), is a measurement standards laboratory which is a non-regulatory agency

of the United States Department of

Commerce. The institute's official mission is to promote U.S. innovation and industrial

competitiveness by advancing measurement science,

standards, and technology in ways that enhance economic security and improve quality of life.

Answer option D is incorrect. The Federal Information Processing Standards (FIPS) are publicly

announced standards developed by the United

States federal government for use by all non-military government agencies and by government

contractors. Many FIPS standards are modified

Some FIPS standards were originally developed by the U.S. government. For instance, standards for

encoding data (e.g., country codes), but

more significantly some encryption standards, such as the Data Encryption Standard (FIPS 46-3) and

the Advanced Encryption Standard (FIPS

197). In 1994, NOAA (Noaa) began broadcasting coded signals called FIPS (Federal Information

Processing System) codes along with their

standard weather broadcasts from local stations. These codes identify the type of emergency and

the specific geographic area (such as a

county) affected by the emergency.


Contribute your Thoughts:

0/2000 characters
Harris
4 months ago
Wait, all of them need to be certified? That seems excessive!
upvoted 0 times
...
Kris
4 months ago
I agree, NIST and FISMA are must-haves!
upvoted 0 times
...
Thurman
4 months ago
FIPS? Not sure if that one applies here.
upvoted 0 times
...
Kris
4 months ago
I think OMB is also involved, right?
upvoted 0 times
...
Carlee
4 months ago
Definitely NIST and FISMA! They’re key for certifying systems.
upvoted 0 times
...
Kristofer
5 months ago
I feel like OMB might be involved too, but I can't recall the specifics on their role in certification.
upvoted 0 times
...
William
5 months ago
I'm not too sure about FISMA, but I remember it has something to do with federal information security.
upvoted 0 times
...
Kimberlie
5 months ago
I think NIST is definitely one of the correct answers since they set the standards for security and accreditation.
upvoted 0 times
...
Erinn
5 months ago
FIPS seems more related to standards rather than the accreditation process, so I'm leaning towards excluding that one.
upvoted 0 times
...
Charolette
5 months ago
I feel like cost is always a concern, but I would prioritize forecasting capabilities to ensure accuracy across different time frames.
upvoted 0 times
...
Leana
5 months ago
Hmm, this seems like a tricky one. I'll need to think through the dependencies carefully to make sure the installation and safety inspection are executed in the right order.
upvoted 0 times
...
Pamela
5 months ago
Okay, I've got this. Agnostic and reusable is the way to go - that's the core of a well-designed service.
upvoted 0 times
...
Michal
5 months ago
Hmm, the options cover a range of software development strategies. I'll need to carefully consider which one best describes Cisco's approach.
upvoted 0 times
...

Save Cancel