nerdexam
(ISC)2

CGRC · Question #268

During which RMF step is the system security plan initially approved? Response:

The correct answer is C. RMF STEP 3. The system security plan is initially approved during Step 3 (Implement) of the Risk Management Framework (RMF), which follows the preparation and categorization phases. This approval signifies that the planned security controls are documented and ready for implementation.

Selection and Approval of Framework, Security, and Privacy Controls

Question

During which RMF step is the system security plan initially approved? Response:

Options

  • ARMF STEP 1
  • BRMF STEP 12
  • CRMF STEP 3
  • DRMF STEP 5

How the community answered

(39 responses)
  • A
    8% (3)
  • C
    90% (35)
  • D
    3% (1)

Why each option

The system security plan is initially approved during Step 3 (Implement) of the Risk Management Framework (RMF), which follows the preparation and categorization phases. This approval signifies that the planned security controls are documented and ready for implementation.

ARMF STEP 1

RMF Step 1 is "Prepare," where foundational activities like defining the risk management strategy and roles occur, but the SSP isn't approved for implementation yet.

BRMF STEP 12

RMF only has six or seven steps depending on the version (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor). There is no "RMF STEP 12."

CRMF STEP 3Correct

In the NIST Risk Management Framework (RMF), the System Security Plan (SSP) is initially approved during Step 3, "Implement." While the SSP is developed and refined in earlier steps (Categorize and Select), the approval to proceed with implementation based on the documented plan occurs in Step 3, signifying a formal commitment to the chosen security controls.

DRMF STEP 5

RMF Step 5 is "Authorize," which is where the authorizing official makes the final risk acceptance decision and grants the authorization to operate, not the initial approval of the SSP for implementation.

Concept tested: RMF steps - SSP approval point

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#RMF Steps#System Security Plan (SSP)#Control Selection#Authorization Process

Community Discussion

No community discussion yet for this question.

Full CGRC Practice