CGRC · Question #268
During which RMF step is the system security plan initially approved? Response:
The correct answer is C. RMF STEP 3. The system security plan is initially approved during Step 3 (Implement) of the Risk Management Framework (RMF), which follows the preparation and categorization phases. This approval signifies that the planned security controls are documented and ready for implementation.
Question
During which RMF step is the system security plan initially approved? Response:
Options
- ARMF STEP 1
- BRMF STEP 12
- CRMF STEP 3
- DRMF STEP 5
How the community answered
(39 responses)- A8% (3)
- C90% (35)
- D3% (1)
Why each option
The system security plan is initially approved during Step 3 (Implement) of the Risk Management Framework (RMF), which follows the preparation and categorization phases. This approval signifies that the planned security controls are documented and ready for implementation.
RMF Step 1 is "Prepare," where foundational activities like defining the risk management strategy and roles occur, but the SSP isn't approved for implementation yet.
RMF only has six or seven steps depending on the version (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor). There is no "RMF STEP 12."
In the NIST Risk Management Framework (RMF), the System Security Plan (SSP) is initially approved during Step 3, "Implement." While the SSP is developed and refined in earlier steps (Categorize and Select), the approval to proceed with implementation based on the documented plan occurs in Step 3, signifying a formal commitment to the chosen security controls.
RMF Step 5 is "Authorize," which is where the authorizing official makes the final risk acceptance decision and grants the authorization to operate, not the initial approval of the SSP for implementation.
Concept tested: RMF steps - SSP approval point
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.