nerdexam
(ISC)2

CGRC · Question #151

The tiers of the NIST RMF are Response:

The correct answer is C. Organization, mission/business process, information system.. The NIST Risk Management Framework (RMF) structures risk management activities across three distinct organizational tiers to ensure comprehensive security integration.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The tiers of the NIST RMF are Response:

Options

  • AOperational, management, system.
  • BConfidentiality, integrity, availability.
  • COrganization, mission/business process, information system.
  • DPrevention, detection, recovery.

How the community answered

(51 responses)
  • B
    2% (1)
  • C
    94% (48)
  • D
    4% (2)

Why each option

The NIST Risk Management Framework (RMF) structures risk management activities across three distinct organizational tiers to ensure comprehensive security integration.

AOperational, management, system.

These terms (operational, management, system) are generic security domains but do not represent the official tiers of the NIST RMF.

BConfidentiality, integrity, availability.

Confidentiality, integrity, and availability (CIA) are the core pillars of information security, not the tiers of the NIST RMF.

COrganization, mission/business process, information system.Correct

The NIST RMF defines three organizational tiers for managing risk: the Organization tier, which focuses on enterprise-wide risk; the Mission/Business Process tier, which addresses risk within specific operational functions; and the Information System tier, which deals with risk directly related to individual systems. These tiers provide a hierarchical approach to understanding and mitigating security risks from a strategic to an operational level.

DPrevention, detection, recovery.

Prevention, detection, and recovery are stages or types of security controls and incident response, not the defined tiers of the NIST RMF.

Concept tested: NIST RMF organizational tiers

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#NIST RMF#RMF tiers#Organizational structure#Risk Management Framework

Community Discussion

No community discussion yet for this question.

Full CGRC Practice