nerdexam
(ISC)2

CGRC · Question #35

The emphasis of the revised NIST SP 800-37 process is on............. Response:

The correct answer is A. Building information security controls into government information systems by applying up-to-date B. Maintaining awareness of the security posture of information systems through the application of C. Providing senior leaders essential information to facilitate decision making with regard to risk. The revised NIST SP 800-37 emphasizes integrating security into the system development lifecycle, continuous monitoring, and providing risk-based information for senior leadership decision-making.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The emphasis of the revised NIST SP 800-37 process is on............. Response:

Options

  • ABuilding information security controls into government information systems by applying up-to-date
  • BMaintaining awareness of the security posture of information systems through the application of
  • CProviding senior leaders essential information to facilitate decision making with regard to risk
  • DCreating secured environment to provide guidance to individuals involved in security information
  • EDeveloping leadership to use, analyze and manage technical security of government information

How the community answered

(39 responses)
  • A
    92% (36)
  • D
    3% (1)
  • E
    5% (2)

Why each option

The revised NIST SP 800-37 emphasizes integrating security into the system development lifecycle, continuous monitoring, and providing risk-based information for senior leadership decision-making.

ABuilding information security controls into government information systems by applying up-to-dateCorrect

A core emphasis of the revised RMF (NIST SP 800-37) is to shift from a static, point-in-time assessment to building security controls directly into the system development life cycle, making security an integral part of the engineering process from the beginning.

BMaintaining awareness of the security posture of information systems through the application ofCorrect

Continuous monitoring is a fundamental aspect of the revised RMF, ensuring that organizations maintain ongoing awareness of the security posture of their information systems and adapt to changing threats and vulnerabilities. This involves constant assessment and response.

CProviding senior leaders essential information to facilitate decision making with regard to riskCorrect

The RMF is designed to provide senior leaders, including authorizing officials, with the necessary information to make informed, risk-based decisions about system authorization and ongoing operation. It connects technical security to organizational risk management.

DCreating secured environment to provide guidance to individuals involved in security information

While the RMF aims to create a secured environment and provides guidance, this statement is too general and does not capture the specific emphasis of the revised SP 800-37 as well as the other options.

EDeveloping leadership to use, analyze and manage technical security of government information

This option is partially covered by (C) but is not as comprehensive in describing the emphasis of the RMF revision, which focuses on the framework's operational aspects rather than just leadership development.

Concept tested: NIST SP 800-37 RMF emphasis

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST SP 800-37#Risk Management Framework (RMF)#Continuous Monitoring#Risk-based Decision Making

Community Discussion

No community discussion yet for this question.

Full CGRC Practice