CGRC · Question #210
What is RMF Step 4? Response:
The correct answer is A. Assess Controls. This question requires identifying the fourth step in the NIST Risk Management Framework (RMF).
Question
What is RMF Step 4? Response:
Options
- AAssess Controls
- BImplement Controls
- CAuthorize
- DSelect Controls
How the community answered
(37 responses)- A86% (32)
- B3% (1)
- C8% (3)
- D3% (1)
Why each option
This question requires identifying the fourth step in the NIST Risk Management Framework (RMF).
RMF Step 4 is 'Assess Controls.' In this step, organizations conduct security and privacy control assessments to determine if the controls are implemented correctly, operating as intended, and achieving the desired security and privacy outcomes, preparing for the authorization decision.
Implement Controls is RMF Step 3, where selected controls are deployed within the system.
Authorize is RMF Step 5, where the senior official makes a risk-based decision to authorize the system's operation.
Select Controls is RMF Step 2, where appropriate security and privacy controls are chosen based on the system's categorization and risk assessment.
Concept tested: NIST RMF steps
Source: https://csrc.nist.gov/projects/risk-management-framework/rmf-steps
Topics
Community Discussion
No community discussion yet for this question.