nerdexam
(ISC)2

CGRC · Question #210

What is RMF Step 4? Response:

The correct answer is A. Assess Controls. This question requires identifying the fourth step in the NIST Risk Management Framework (RMF).

Assessment/Audit of Security and Privacy Controls

Question

What is RMF Step 4? Response:

Options

  • AAssess Controls
  • BImplement Controls
  • CAuthorize
  • DSelect Controls

How the community answered

(37 responses)
  • A
    86% (32)
  • B
    3% (1)
  • C
    8% (3)
  • D
    3% (1)

Why each option

This question requires identifying the fourth step in the NIST Risk Management Framework (RMF).

AAssess ControlsCorrect

RMF Step 4 is 'Assess Controls.' In this step, organizations conduct security and privacy control assessments to determine if the controls are implemented correctly, operating as intended, and achieving the desired security and privacy outcomes, preparing for the authorization decision.

BImplement Controls

Implement Controls is RMF Step 3, where selected controls are deployed within the system.

CAuthorize

Authorize is RMF Step 5, where the senior official makes a risk-based decision to authorize the system's operation.

DSelect Controls

Select Controls is RMF Step 2, where appropriate security and privacy controls are chosen based on the system's categorization and risk assessment.

Concept tested: NIST RMF steps

Source: https://csrc.nist.gov/projects/risk-management-framework/rmf-steps

Topics

#RMF#NIST#Control Assessment#RMF Steps

Community Discussion

No community discussion yet for this question.

Full CGRC Practice