CGRC · Question #183
The RMF Step and task where the Categorization of the information and IS is done and results documented in the Security Plan (SP) Response:
The correct answer is D. RMF Step 1, Task 1. In the NIST Risk Management Framework (RMF), the initial categorization of information and information systems, along with documenting the results in the Security Plan (SP), occurs in Step 1, Task 1.
Question
The RMF Step and task where the Categorization of the information and IS is done and results documented in the Security Plan (SP) Response:
Options
- ARMF Step 1, Task 2
- BRMF Step 1, Task 3
- CRMF Step 1, Task 4
- DRMF Step 1, Task 1
How the community answered
(51 responses)- A2% (1)
- C4% (2)
- D94% (48)
Why each option
In the NIST Risk Management Framework (RMF), the initial categorization of information and information systems, along with documenting the results in the Security Plan (SP), occurs in Step 1, Task 1.
RMF Step 1, Task 2 typically involves selecting security controls, which happens after categorization.
RMF Step 1, Task 3 usually relates to tailoring and supplementing the selected security controls.
RMF Step 1, Task 4 is associated with developing a monitoring strategy, which follows control selection and tailoring.
According to NIST SP 800-37, the first step of the Risk Management Framework is "Categorize System." Task 1-1 within this step is "Categorize Information System," which involves defining the system boundary, identifying information types, and assigning a security impact level (Confidentiality, Integrity, Availability) for the information and the system, with the results documented in the Security Plan.
Concept tested: NIST RMF Step 1 Task 1 - System Categorization
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.