Soru

Zorluk: OrtaRegulatory Compliance and Legal Requirements Management

A defense contracting firm is deploying a cloud-based information system to store and process Controlled Unclassified Information (CUI) for federal procurement projects. To fulfill federal regulatory requirements for safeguarding CUI residing in non-federal systems, which compliance framework must the firm implement?

  1. NIST SP 800-171 standards for protecting Controlled Unclassified Information in non-federal systemsCevap
  2. B
    Payment Card Industry Data Security Standard (PCI-DSS) technical requirements for cardholder data environments
  3. C
    Health Insurance Portability and Accountability Act (HIPAA) Security Rule baseline safeguards
  4. D
    Sarbanes-Oxley Act (SOX) Section 404 financial internal accounting controls

Cevap

Implementing NIST SP 800-171 standards specifically addresses the security requirements for protecting Controlled Unclassified Information (CUI) stored or processed in non-federal environments.
NIST SP 800-171 provides the specified security controls for protecting the confidentiality of Controlled Unclassified Information (CUI) when held by non-federal entities, such as government contractors and subcontractors.

Adım Adım Çözüm

1
Identify the data classification and organizational context.
The scenario involves Controlled Unclassified Information (CUI) handled by a non-federal defense contractor.
Federal regulations mandate specific frameworks depending on data classification and entity type.
2
Match the compliance framework governing CUI in non-federal systems.
NIST Special Publication 800-171 is explicitly designed to safeguard CUI in non-federal information systems and organizations.
Federal defense procurement regulations (such as DFARS) require contractors to implement NIST SP 800-171 controls.

Anahtar Kavram

Federal and Regulatory Compliance Frameworks for Information Safeguarding
Bu soruyu puanla