PPS 3
Cyber Laws
Frameworks
RMF Workflows
Artifacts
100

This simple service runs over port 25 and is associated with mail clients.

What is SMTP?

(Simple Mail Transfer Protocol)

100

This modernization act defines a framework of guidelines and security standards to protect government information and operations

What is FISMA?

(Federal Information System Modernization Act)

100

This framework for assessing and authorizing systems is widely used by the DoD

What is RMF?

(Risk Management Framework)

100

When creating an information system, this artifact/process identifies the system, its personnel, and the information types intended for use in the system

What is Information System Categorization?

100

This artifact is responsible for tracking applications registered in DADMS

What is the Software List?

(Hardware, Software, Firmware Diagram acceptable)

200

This windows remote access protocol runs over port 3389 and allows users to open a GUI terminal to operate a system remotely.

What is RDP?

(Remote Desktop Protocol)

200

This law puts standards in place to protect sensitive patient health information from being disclosed without patient consent/knowledge

What is HIPAA?

(Healthcare Insurance Portability and Accountability Act)

200

This standard requires credit card processers to secure cardholder data whenever it is stored, processed, or transmitted.

What is PCI/DSS?


(Payment Card Industry/Data Security Standard)

200

This RMF Step is nicknamed "Continuous Monitoring"

What is RMF Step 6?

200

This artifact is traceable to the hardware list and visually represents each information system component.

What is the authorization boundary diagram?

(Network Topology diagram is also okay!)

300

This monitoring protocol runs over port 161/162 and allows for monitoring and management of network devices.

What is SNMP?

(Simple Network Management Protocol)

300

This law was drafted and passed by the European Union to safeguard the privacy of individuals in the EU

What is GDPR? 

(General Data Protection Regulation)

300

Loosely related to RMF, this NIST framework provides voluntary security controls and best practices for companies to follow

What is the CSF?

(Cybersecurity Framework)

300

This RMF Step typically involves validation and the creation of a Security Assessment Plan

What is RMF Step 4?

300

This artifact is required for assessment and authorization, and asserts what testing has been completed on the information system.

What is the Security Assessment Plan?

400

This port number is assigned to the cleartext syslog service to ship log and event information.

What is Port 514?

400

This law allows US prosecutors to address cyber based crimes pertaining to exceeding authorized access of information systems.

What is Computer Fraud and Abuse Act

400

This ISACA IT governence framework is intented for business to implement best practices for implementation, monitoring, and IT management.

What is COBIT?

400

This RMF Step involves the creation of a System Security Plan that's signed by the NAO prior to validation.

What is RMF Step 2: System Security Plan Approval?

400

This eMASS feature documents the implementation status and monitoring strategy of NIST Controls.

What is the Implementation Plan?
500

This default port allows remote SQL database management

What is Port 1433?

500

This act requires financial instructions to explain information sharing practices to customers and safeguard sensitive data.

What is the Gramm-Leach-Bliley Act?

500

This standardized framework's widely used by healthcare providers to meet information system requirements pertaining to HIPAA

What is HITRUST?

500

This RMF workflow is associated with receiving a SAR from the SCA and an ATO letter from an AO.

What is RMF Steps 4+5: Risk Assessment?

500

This artifact is the outcome of RMF Step 2 and RMF Step 5, representing the AO's concurrence with the system's baseline

What is the signed system security plan?