CGRC · Question #255
What is RMF Step 1? Response:
The correct answer is A. Categorization. The first step in the NIST Risk Management Framework (RMF) is Categorization, where information systems are categorized based on impact.
Question
What is RMF Step 1? Response:
Options
- ACategorization
- BImplement Controls
- CAssess Controls
- DMonitor
How the community answered
(52 responses)- A87% (45)
- B8% (4)
- C2% (1)
- D4% (2)
Why each option
The first step in the NIST Risk Management Framework (RMF) is Categorization, where information systems are categorized based on impact.
According to NIST SP 800-37, the Risk Management Framework (RMF) begins with Step 1: Categorize System. This step involves defining the system's mission, identifying information types, and assigning impact levels for confidentiality, integrity, and availability.
Implement Controls is Step 3 of the RMF, occurring after categorization and selection of controls.
Assess Controls is Step 4 of the RMF, following the implementation of controls.
Monitor is Step 6 of the RMF, representing the ongoing oversight of the system's security posture.
Concept tested: NIST RMF steps - Categorization
Source: https://csrc.nist.gov/projects/risk-management/about-rmf
Topics
Community Discussion
No community discussion yet for this question.