nerdexam
(ISC)2

CGRC · Question #331

Which NIST guide authorizes an organization to tailor system authorization activities to the level of effort and rigor that is suitable for the IS being tested? Response:

The correct answer is A. NIST SP 800-37. NIST Special Publication 800-37 is the guide that authorizes organizations to tailor system authorization activities, including security control implementation and assessment, to align with the system's specific risk posture and operational context.

Selection and Approval of Framework, Security, and Privacy Controls

Question

Which NIST guide authorizes an organization to tailor system authorization activities to the level of effort and rigor that is suitable for the IS being tested? Response:

Options

  • ANIST SP 800-37
  • BNIST SP 800-53
  • CNIST SP 800-39
  • DNIST SP 800-37A

How the community answered

(51 responses)
  • A
    92% (47)
  • B
    4% (2)
  • C
    2% (1)
  • D
    2% (1)

Why each option

NIST Special Publication 800-37 is the guide that authorizes organizations to tailor system authorization activities, including security control implementation and assessment, to align with the system's specific risk posture and operational context.

ANIST SP 800-37Correct

NIST SP 800-37, "Guide for Applying the Risk Management Framework to Federal Information Systems," explicitly details the RMF steps, including the authorization step where organizations can tailor security controls and authorization activities to match the system's mission, criticality, and risk posture. This tailoring ensures that the level of effort and rigor applied is appropriate for the specific information system being authorized.

BNIST SP 800-53

NIST SP 800-53 defines the catalog of security and privacy controls but does not authorize or guide the tailoring of authorization activities itself.

CNIST SP 800-39

NIST SP 800-39 focuses on enterprise-wide risk management principles and framework, not the specific tailoring of system authorization activities within the RMF.

DNIST SP 800-37A

While NIST SP 800-37A is related to security assessments, it is a supplement to 800-37 and not the primary guide that authorizes or explains the overarching tailoring of authorization activities within the RMF.

Concept tested: NIST RMF tailoring and authorization

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST SP 800-37#Risk Management Framework (RMF)#System Authorization#Tailoring

Community Discussion

No community discussion yet for this question.

Full CGRC Practice