CAP · Question #289
In which of the following Risk Management Framework (RMF) phases is strategic risk assessment planning performed?
The correct answer is A. Phase 0. Phase 0 of the NIST Risk Management Framework is the Prepare phase, where strategic risk assessment planning and organization-wide risk management foundations are established.
Question
In which of the following Risk Management Framework (RMF) phases is strategic risk assessment planning performed?
Options
- APhase 0
- BPhase 1
- CPhase 2
- DPhase 3
How the community answered
(25 responses)- A96% (24)
- D4% (1)
Why each option
Phase 0 of the NIST Risk Management Framework is the Prepare phase, where strategic risk assessment planning and organization-wide risk management foundations are established.
RMF Phase 0 (Prepare) involves establishing the context, priorities, and risk management strategy at both the organizational and system levels before system-specific steps begin. Strategic risk assessment planning - including defining risk tolerance, identifying key stakeholders, and establishing a risk management strategy - is performed during this phase as a foundational activity per NIST SP 800-37 Rev 2.
Phase 1 is the Categorize phase, where information systems are categorized based on impact levels using FIPS 199 and NIST SP 800-60.
Phase 2 is the Select phase, where security and privacy controls are selected based on the system's impact categorization using NIST SP 800-53.
Phase 3 is the Implement phase, where the selected security controls are actually deployed and documented within the information system.
Concept tested: NIST RMF Phase 0 - Prepare and strategic risk planning
Source: https://csrc.nist.gov/projects/risk-management/about-rmf
Topics
Community Discussion
No community discussion yet for this question.