FITSP EXAM REVIEW QUESTIONS WITH
ACCURATE SOLUTIONS 2026
▶ The "3's" of special publications addressing risk?. Answer: SP800-30:
Risk Assessment
SP800-37: Risk Management Framework
SP800-137: Continuous Monitoring
SP800-39: Managing Risk, replaced the original SP800-30
▶ What are the three control families as defined by SP800-53r3?. Answer:
1. Management
2. Technical
3. Operational
▶ Implementation of continuous monitoring results in ongoing updates to
what documents?. Answer: Security Plan
Security Assessment Report
Plan of Action and Milestones
▶ Risk Management Strategy. Answer: An unambiguous expression of the
organization's risk tolerance, acceptable risk assessment methodologies,
risk mitigation strategies, a process for evaluation risk across the
organization, and approaches for monitoring risk.
▶ HSPD-7. Answer: Establishes a national policy for federal departments
and agencies to identify and prioritize US critical infrastructure and key
resources and to protect them from terrorist attacks.
▶ SP800-122. Answer: Personally Identifiable Information
▶ SP800-88. Answer: Media Sanitization
▶ What are the acceptable methods of media sanitization?. Answer:
Clearing (low)
Purging (med)
Destroying (high)
, ▶ SP800-34. Answer: Contingency Planning (7 steps)
-Integrates information security into CPIC; The BIA step helps identify the
potential cost impact to account for
▶ What are the 7 steps of the contingency planning process?. Answer: 1.
Develop the contingency planning policy statement
2. Conduct the Business Impact Analysis
3. Identify preventative controls
4. Create contingency strategies
5. Develop an information contingency plan
6. Ensure plan testing, training, and exercises
7. Ensure plan maintenance
(Don't believe I can do that, man)
▶ What is the Risk Management Model/Process?. Answer: FARM:
Frame
Assess
Respond
Monitor
▶ What are the three tiers of Integrated Organization-Wide Risk
Management?. Answer: Tier 1: Organization
Tier 2: Mission/Business Process
Tier 3: Information System
▶ What are the seven Tier 1 risks from an organizational perspective?.
Answer: Strategic
Governance
Methodologies
Techniques and Procedures
Mitigation Methods
Risk Tolerance
Ongoing Monitoring
▶ SP800-37. Answer: Risk Management Framework for Information
Systems and Organizations
-Describes common information security framework for the federal
government
ACCURATE SOLUTIONS 2026
▶ The "3's" of special publications addressing risk?. Answer: SP800-30:
Risk Assessment
SP800-37: Risk Management Framework
SP800-137: Continuous Monitoring
SP800-39: Managing Risk, replaced the original SP800-30
▶ What are the three control families as defined by SP800-53r3?. Answer:
1. Management
2. Technical
3. Operational
▶ Implementation of continuous monitoring results in ongoing updates to
what documents?. Answer: Security Plan
Security Assessment Report
Plan of Action and Milestones
▶ Risk Management Strategy. Answer: An unambiguous expression of the
organization's risk tolerance, acceptable risk assessment methodologies,
risk mitigation strategies, a process for evaluation risk across the
organization, and approaches for monitoring risk.
▶ HSPD-7. Answer: Establishes a national policy for federal departments
and agencies to identify and prioritize US critical infrastructure and key
resources and to protect them from terrorist attacks.
▶ SP800-122. Answer: Personally Identifiable Information
▶ SP800-88. Answer: Media Sanitization
▶ What are the acceptable methods of media sanitization?. Answer:
Clearing (low)
Purging (med)
Destroying (high)
, ▶ SP800-34. Answer: Contingency Planning (7 steps)
-Integrates information security into CPIC; The BIA step helps identify the
potential cost impact to account for
▶ What are the 7 steps of the contingency planning process?. Answer: 1.
Develop the contingency planning policy statement
2. Conduct the Business Impact Analysis
3. Identify preventative controls
4. Create contingency strategies
5. Develop an information contingency plan
6. Ensure plan testing, training, and exercises
7. Ensure plan maintenance
(Don't believe I can do that, man)
▶ What is the Risk Management Model/Process?. Answer: FARM:
Frame
Assess
Respond
Monitor
▶ What are the three tiers of Integrated Organization-Wide Risk
Management?. Answer: Tier 1: Organization
Tier 2: Mission/Business Process
Tier 3: Information System
▶ What are the seven Tier 1 risks from an organizational perspective?.
Answer: Strategic
Governance
Methodologies
Techniques and Procedures
Mitigation Methods
Risk Tolerance
Ongoing Monitoring
▶ SP800-37. Answer: Risk Management Framework for Information
Systems and Organizations
-Describes common information security framework for the federal
government