CGRC · Question #335
Which of the following guidance documents is useful in determining the impact level of a particular threat on agency systems? Response:
The correct answer is B. NIST SP 800-37. NIST SP 800-37, "Guide for Applying the Risk Management Framework," provides the overall process that an organization follows to categorize information systems (using FIPS 199) and then assess the potential impact of threats on those categorized systems.
Question
Which of the following guidance documents is useful in determining the impact level of a particular threat on agency systems? Response:
Options
- ANIST SP 800-41
- BNIST SP 800-37
- CFIPS 199
- DNIST SP 800-14
How the community answered
(59 responses)- A2% (1)
- B93% (55)
- C2% (1)
- D3% (2)
Why each option
NIST SP 800-37, "Guide for Applying the Risk Management Framework," provides the overall process that an organization follows to categorize information systems (using FIPS 199) and then assess the potential impact of threats on those categorized systems.
NIST SP 800-41 provides guidelines for firewalls and firewall policy, which is not directly related to determining the impact level of a threat on agency systems.
NIST SP 800-37, which outlines the Risk Management Framework, includes the initial step of categorizing information systems based on the potential impact of a security event (as defined by FIPS 199). This foundational categorization, guided by SP 800-37, is crucial for understanding and determining the impact level of any particular threat that could affect the system's confidentiality, integrity, or availability.
FIPS 199 defines the Low, Moderate, and High impact levels for information and information systems, but it is a standard for categorization, not a guide for the process of determining a specific threat's impact level as applied within a risk management framework.
NIST SP 800-14 is an older document discussing generally accepted principles and practices for securing IT systems, which is too broad and not specifically focused on determining threat impact levels.
Concept tested: NIST RMF and threat impact assessment
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.