nerdexam
(ISC)2

CGRC · Question #255

What is RMF Step 1? Response:

The correct answer is A. Categorization. The first step in the NIST Risk Management Framework (RMF) is Categorization, where information systems are categorized based on impact.

Scope of the System

Question

What is RMF Step 1? Response:

Options

  • ACategorization
  • BImplement Controls
  • CAssess Controls
  • DMonitor

How the community answered

(52 responses)
  • A
    87% (45)
  • B
    8% (4)
  • C
    2% (1)
  • D
    4% (2)

Why each option

The first step in the NIST Risk Management Framework (RMF) is Categorization, where information systems are categorized based on impact.

ACategorizationCorrect

According to NIST SP 800-37, the Risk Management Framework (RMF) begins with Step 1: Categorize System. This step involves defining the system's mission, identifying information types, and assigning impact levels for confidentiality, integrity, and availability.

BImplement Controls

Implement Controls is Step 3 of the RMF, occurring after categorization and selection of controls.

CAssess Controls

Assess Controls is Step 4 of the RMF, following the implementation of controls.

DMonitor

Monitor is Step 6 of the RMF, representing the ongoing oversight of the system's security posture.

Concept tested: NIST RMF steps - Categorization

Source: https://csrc.nist.gov/projects/risk-management/about-rmf

Topics

#RMF#NIST SP 800-37#System Categorization#RMF Steps

Community Discussion

No community discussion yet for this question.

Full CGRC Practice