In the IA Policy and Standard set, which item is designated as the policy reference?

Enhance your preparation for the Federal IT Security Professional Test. Use quizzes, flashcards, and detailed explanations to ensure success. Stay ahead in the field of IT Security!

Multiple Choice

In the IA Policy and Standard set, which item is designated as the policy reference?

Explanation:
In this context, the item designated as the policy reference is the overarching directive that sets the rules for identity and access across the federal government. HSPD-12 is Homeland Security Presidential Directive 12, which establishs the requirement for a common, secure form of identification for federal employees and contractors and provides the policy framework for both physical and logical access controls. That makes it the policy reference in the IA Policy and Standard set. The other items define how to implement that policy or specify technical and interoperability details. FIPS 201-1 translates the policy into a credentialing standard for a personal identity verification system, while PIV-1 security requirements and PIV-11 technical interoperability requirements lay out specific security controls and interoperability criteria for the PIV system. While essential, they are implementation and technical requirements, not the policy reference itself.

In this context, the item designated as the policy reference is the overarching directive that sets the rules for identity and access across the federal government. HSPD-12 is Homeland Security Presidential Directive 12, which establishs the requirement for a common, secure form of identification for federal employees and contractors and provides the policy framework for both physical and logical access controls. That makes it the policy reference in the IA Policy and Standard set.

The other items define how to implement that policy or specify technical and interoperability details. FIPS 201-1 translates the policy into a credentialing standard for a personal identity verification system, while PIV-1 security requirements and PIV-11 technical interoperability requirements lay out specific security controls and interoperability criteria for the PIV system. While essential, they are implementation and technical requirements, not the policy reference itself.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy