nerdexam
(ISC)2

CGRC · Question #335

Which of the following guidance documents is useful in determining the impact level of a particular threat on agency systems? Response:

The correct answer is B. NIST SP 800-37. NIST SP 800-37, "Guide for Applying the Risk Management Framework," provides the overall process that an organization follows to categorize information systems (using FIPS 199) and then assess the potential impact of threats on those categorized systems.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following guidance documents is useful in determining the impact level of a particular threat on agency systems? Response:

Options

  • ANIST SP 800-41
  • BNIST SP 800-37
  • CFIPS 199
  • DNIST SP 800-14

How the community answered

(59 responses)
  • A
    2% (1)
  • B
    93% (55)
  • C
    2% (1)
  • D
    3% (2)

Why each option

NIST SP 800-37, "Guide for Applying the Risk Management Framework," provides the overall process that an organization follows to categorize information systems (using FIPS 199) and then assess the potential impact of threats on those categorized systems.

ANIST SP 800-41

NIST SP 800-41 provides guidelines for firewalls and firewall policy, which is not directly related to determining the impact level of a threat on agency systems.

BNIST SP 800-37Correct

NIST SP 800-37, which outlines the Risk Management Framework, includes the initial step of categorizing information systems based on the potential impact of a security event (as defined by FIPS 199). This foundational categorization, guided by SP 800-37, is crucial for understanding and determining the impact level of any particular threat that could affect the system's confidentiality, integrity, or availability.

CFIPS 199

FIPS 199 defines the Low, Moderate, and High impact levels for information and information systems, but it is a standard for categorization, not a guide for the process of determining a specific threat's impact level as applied within a risk management framework.

DNIST SP 800-14

NIST SP 800-14 is an older document discussing generally accepted principles and practices for securing IT systems, which is too broad and not specifically focused on determining threat impact levels.

Concept tested: NIST RMF and threat impact assessment

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST RMF#Impact Level Determination#System Categorization#NIST SP 800-37

Community Discussion

No community discussion yet for this question.

Full CGRC Practice