CGRC · Question #151
The tiers of the NIST RMF are Response:
The correct answer is C. Organization, mission/business process, information system.. The NIST Risk Management Framework (RMF) structures risk management activities across three distinct organizational tiers to ensure comprehensive security integration.
Question
The tiers of the NIST RMF are Response:
Options
- AOperational, management, system.
- BConfidentiality, integrity, availability.
- COrganization, mission/business process, information system.
- DPrevention, detection, recovery.
How the community answered
(51 responses)- B2% (1)
- C94% (48)
- D4% (2)
Why each option
The NIST Risk Management Framework (RMF) structures risk management activities across three distinct organizational tiers to ensure comprehensive security integration.
These terms (operational, management, system) are generic security domains but do not represent the official tiers of the NIST RMF.
Confidentiality, integrity, and availability (CIA) are the core pillars of information security, not the tiers of the NIST RMF.
The NIST RMF defines three organizational tiers for managing risk: the Organization tier, which focuses on enterprise-wide risk; the Mission/Business Process tier, which addresses risk within specific operational functions; and the Information System tier, which deals with risk directly related to individual systems. These tiers provide a hierarchical approach to understanding and mitigating security risks from a strategic to an operational level.
Prevention, detection, and recovery are stages or types of security controls and incident response, not the defined tiers of the NIST RMF.
Concept tested: NIST RMF organizational tiers
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.