Which requirement does the Computer Security Act of 1987 mandate for federal computer systems that contain sensitive information?

Enhance your preparation for the Federal IT Security Professional Test. Use quizzes, flashcards, and detailed explanations to ensure success. Stay ahead in the field of IT Security!

Multiple Choice

Which requirement does the Computer Security Act of 1987 mandate for federal computer systems that contain sensitive information?

Explanation:
The main concept is that federal agencies must create a formal framework for protecting sensitive information in their computer systems. The Computer Security Act of 1987 directs agencies to develop and implement security policies and procedures for information systems that handle sensitive data, designate a security official, and establish security plans for major systems. It also assigns the responsibility to NIST to develop standards and guidelines to support those policies and planning. This is about building a policy and planning foundation for information security, not mandating encryption of all data at rest, outsourcing security to contractors, or making logs openly accessible, which are not requirements of this act.

The main concept is that federal agencies must create a formal framework for protecting sensitive information in their computer systems. The Computer Security Act of 1987 directs agencies to develop and implement security policies and procedures for information systems that handle sensitive data, designate a security official, and establish security plans for major systems. It also assigns the responsibility to NIST to develop standards and guidelines to support those policies and planning. This is about building a policy and planning foundation for information security, not mandating encryption of all data at rest, outsourcing security to contractors, or making logs openly accessible, which are not requirements of this act.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy