CISM Information Security Programme Practice Question
Which control family in NIST SP 800-53 addresses the identification and authentication of users?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identification and Authentication (IA)
The Identification and Authentication (IA) family in NIST SP 800-53 covers user identification, authentication, and credential management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Personnel Security (PS)
Why it's wrong here
PS covers personnel screening, termination and training controls, not technical user authentication. It is tempting because identity assurance involves people. PS would be correct when the requirement concerns workforce suitability, background checks or offboarding rather than system login verification.
- ✓
Identification and Authentication (IA)
Why this is correct
NIST SP 800-53's Identification and Authentication (IA) family directly governs user identity verification and credential management, satisfying the stem's requirement for the control family addressing user identification and authentication. IA controls cover authenticator management, identity proofing and session authentication, making it the precise match rather than access control or audit families.
- ✗
System and Communications Protection (SC)
Why it's wrong here
SC addresses protecting communications and system boundaries through encryption, integrity and transmission safeguards, not user identity verification. It is tempting because authentication traffic often needs protection. SC would be correct when the requirement concerns securing data in transit or hardening system boundaries.
- ✗
Access Control (AC)
Why it's wrong here
Access Control (AC) governs authorisation decisions and enforcement of permitted actions after identity is established. It is tempting because authentication gates access, yet NIST SP 800-53 places identification and authentication requirements in the Identification and Authentication (IA) family, so AC does not address them.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.