nerdexam
(ISC)2

CGRC · Question #271

Which of the following RMF phases identifies key threats and vulnerabilities that could compromise the confidentiality, integrity, and availability of the institutional critical assets? Response:

The correct answer is B. Phase 1. Phase 1 of the Risk Management Framework (RMF), known as Prepare, involves identifying organizational assets, threats, and vulnerabilities that could impact confidentiality, integrity, and availability.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following RMF phases identifies key threats and vulnerabilities that could compromise the confidentiality, integrity, and availability of the institutional critical assets? Response:

Options

  • APhase 2
  • BPhase 1
  • CPhase 3
  • DPhase 0

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    92% (23)
  • C
    4% (1)

Why each option

Phase 1 of the Risk Management Framework (RMF), known as Prepare, involves identifying organizational assets, threats, and vulnerabilities that could impact confidentiality, integrity, and availability.

APhase 2

Phase 2 (Categorize) is about categorizing the information system based on impact, not directly identifying threats and vulnerabilities of assets.

BPhase 1Correct

In the NIST Risk Management Framework, Phase 1 (Prepare) focuses on understanding the organizational context, including identifying critical assets, potential threats, and system vulnerabilities, to establish a foundation for risk management activities. This initial phase sets the stage by defining the scope and parameters for subsequent risk assessment and mitigation efforts.

CPhase 3

Phase 3 (Select) involves selecting security controls, which happens after threats and vulnerabilities have been identified.

DPhase 0

Phase 0 is not a recognized formal phase in the NIST RMF.

Concept tested: RMF Prepare phase activities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#RMF Categorize Phase#Threat Identification#Vulnerability Identification#NIST RMF

Community Discussion

No community discussion yet for this question.

Full CGRC Practice