CGRC · Question #211
Which NIST SP details how RMF can be integrated into the System Development Life-Cycle (SDLC)? Response:
The correct answer is A. NIST SP 800-37. NIST SP 800-37, titled "Risk Management Framework for Information Systems and Organizations," provides the detailed guidance on how to integrate the RMF into the System Development Life-Cycle (SDLC). It outlines a comprehensive process for managing security and privacy risk throu
Question
Which NIST SP details how RMF can be integrated into the System Development Life-Cycle (SDLC)? Response:
Options
- ANIST SP 800-37
- BNIST SP 800-39
- CNIST SP 800-53
- DNIST SP 800-37A
How the community answered
(45 responses)- A87% (39)
- B4% (2)
- C2% (1)
- D7% (3)
Why each option
NIST SP 800-37, titled "Risk Management Framework for Information Systems and Organizations," provides the detailed guidance on how to integrate the RMF into the System Development Life-Cycle (SDLC). It outlines a comprehensive process for managing security and privacy risk throughout the system's lifecycle.
NIST SP 800-37, specifically Revision 2, details the six steps of the Risk Management Framework (RMF) and explicitly explains how these steps should be integrated into the System Development Life-Cycle (SDLC) to ensure security and privacy are built into information systems from the ground up.
NIST SP 800-39 focuses on enterprise-wide risk management, not specifically the integration of RMF into the SDLC.
NIST SP 800-53 provides the security and privacy controls for federal information systems, which are used within the RMF, but it does not detail RMF-SDLC integration.
NIST SP 800-37A is an older, withdrawn document, superseded by later revisions of SP 800-37, and does not provide current guidance for RMF-SDLC integration.
Concept tested: NIST RMF and SDLC integration
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.