nerdexam
(ISC)2

CGRC · Question #117

Which of the following are phases of the NIST RMF? Response:

The correct answer is A. Categorize, select, implement, assess, authorize. The question asks to identify the correct sequence of phases within the NIST Risk Management Framework (RMF).

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following are phases of the NIST RMF? Response:

Options

  • ACategorize, select, implement, assess, authorize
  • BAssess, certify, accredit, manage
  • CPrepare, execute, authorize, monitor
  • DAssess, mitigate, authorize, monitor

How the community answered

(33 responses)
  • A
    88% (29)
  • B
    3% (1)
  • C
    3% (1)
  • D
    6% (2)

Why each option

The question asks to identify the correct sequence of phases within the NIST Risk Management Framework (RMF).

ACategorize, select, implement, assess, authorizeCorrect

The core steps of the NIST RMF include Categorize, Select, Implement, Assess, Authorize, and Monitor, with 'Prepare' as an initial phase. This option lists five of these seven crucial phases in the correct order, which are fundamental to managing information security risk for federal systems.

BAssess, certify, accredit, manage

The terms 'Certify' and 'Accredit' are associated with older frameworks like DIACAP, not the current NIST RMF phases.

CPrepare, execute, authorize, monitor

'Execute' is not a formal RMF phase; 'Prepare' is the initial phase in the current RMF.

DAssess, mitigate, authorize, monitor

'Mitigate' is an action taken as part of control implementation or response to findings, not a distinct RMF phase.

Concept tested: NIST RMF phases

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST RMF#Risk Management Framework#RMF phases#Security Frameworks

Community Discussion

No community discussion yet for this question.

Full CGRC Practice