CGRC · Question #331
Which NIST guide authorizes an organization to tailor system authorization activities to the level of effort and rigor that is suitable for the IS being tested? Response:
The correct answer is A. NIST SP 800-37. NIST Special Publication 800-37 is the guide that authorizes organizations to tailor system authorization activities, including security control implementation and assessment, to align with the system's specific risk posture and operational context.
Question
Which NIST guide authorizes an organization to tailor system authorization activities to the level of effort and rigor that is suitable for the IS being tested? Response:
Options
- ANIST SP 800-37
- BNIST SP 800-53
- CNIST SP 800-39
- DNIST SP 800-37A
How the community answered
(51 responses)- A92% (47)
- B4% (2)
- C2% (1)
- D2% (1)
Why each option
NIST Special Publication 800-37 is the guide that authorizes organizations to tailor system authorization activities, including security control implementation and assessment, to align with the system's specific risk posture and operational context.
NIST SP 800-37, "Guide for Applying the Risk Management Framework to Federal Information Systems," explicitly details the RMF steps, including the authorization step where organizations can tailor security controls and authorization activities to match the system's mission, criticality, and risk posture. This tailoring ensures that the level of effort and rigor applied is appropriate for the specific information system being authorized.
NIST SP 800-53 defines the catalog of security and privacy controls but does not authorize or guide the tailoring of authorization activities itself.
NIST SP 800-39 focuses on enterprise-wide risk management principles and framework, not the specific tailoring of system authorization activities within the RMF.
While NIST SP 800-37A is related to security assessments, it is a supplement to 800-37 and not the primary guide that authorizes or explains the overarching tailoring of authorization activities within the RMF.
Concept tested: NIST RMF tailoring and authorization
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.