CGRC · Question #113
The phase 0 of Risk Management Framework (RMF) is known as strategic risk assessment planning. Which of the following processes take place in phase 0? Each correct answer represents a complete…
The correct answer is B. Apply classification criteria to rank data assets and related IT resources. C. Establish criteria that will be used to classify and rank data assets. D. Identify threats, vulnerabilities, and controls that will be evaluated. E. Establish criteria that will be used to evaluate threats, vulnerabilities, and controls. This question asks to identify the specific processes involved in Phase 0 (strategic risk assessment planning) of the Risk Management Framework (RMF).
Question
The phase 0 of Risk Management Framework (RMF) is known as strategic risk assessment planning. Which of the following processes take place in phase 0? Each correct answer represents a complete solution. Choose all that apply. Response:
Options
- AReview documentation and technical data.
- BApply classification criteria to rank data assets and related IT resources.
- CEstablish criteria that will be used to classify and rank data assets.
- DIdentify threats, vulnerabilities, and controls that will be evaluated.
- EEstablish criteria that will be used to evaluate threats, vulnerabilities, and controls.
How the community answered
(42 responses)- A19% (8)
- B81% (34)
Why each option
This question asks to identify the specific processes involved in Phase 0 (strategic risk assessment planning) of the Risk Management Framework (RMF).
Reviewing documentation and technical data is a general activity that might happen throughout various phases, but it's not a core, unique process specifically defining Phase 0 of strategic risk assessment planning in the same way as establishing and applying criteria or identifying scope.
Phase 0, or strategic risk assessment planning, focuses on foundational activities such as establishing criteria for classifying data assets (C) and then applying them (B). It also includes identifying the scope of threats, vulnerabilities, and controls to be assessed (D), and establishing the criteria for their evaluation (E).
Phase 0, or strategic risk assessment planning, focuses on foundational activities such as establishing criteria for classifying data assets (C) and then applying them (B). It also includes identifying the scope of threats, vulnerabilities, and controls to be assessed (D), and establishing the criteria for their evaluation (E).
Phase 0, or strategic risk assessment planning, focuses on foundational activities such as establishing criteria for classifying data assets (C) and then applying them (B). It also includes identifying the scope of threats, vulnerabilities, and controls to be assessed (D), and establishing the criteria for their evaluation (E).
Phase 0, or strategic risk assessment planning, focuses on foundational activities such as establishing criteria for classifying data assets (C) and then applying them (B). It also includes identifying the scope of threats, vulnerabilities, and controls to be assessed (D), and establishing the criteria for their evaluation (E).
Concept tested: RMF strategic risk assessment planning activities
Topics
Community Discussion
No community discussion yet for this question.