nerdexam
(ISC)2

CGRC · Question #368

Step 6 of the risk management framework can be described as: Response:

The correct answer is D. The post-authorization phase of the system authorization plan. This question asks to characterize Step 6 of the NIST Risk Management Framework (RMF).

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Step 6 of the risk management framework can be described as:

Response:

Options

  • AThe certification phase of the system authorization plan
  • BThe pre-certification phase of the system authorization plan
  • CThe authorization phase of the system authorization plan
  • DThe post-authorization phase of the system authorization plan

How the community answered

(50 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    90% (45)

Why each option

This question asks to characterize Step 6 of the NIST Risk Management Framework (RMF).

AThe certification phase of the system authorization plan

“Certification” often refers to the assessment process (Step 4), but Step 6 is distinct and focuses on ongoing operations.

BThe pre-certification phase of the system authorization plan

The pre-certification phase would involve initial planning and implementation steps (Steps 1-3).

CThe authorization phase of the system authorization plan

The "Authorization" phase is specifically Step 5 of the RMF, where the official decision is made, not Step 6.

DThe post-authorization phase of the system authorization planCorrect

Step 6 of the NIST RMF is "Monitor," which involves continuous monitoring of the information system and its controls after the system has received its initial authorization to operate. This phase ensures ongoing effectiveness and compliance, making it the post-authorization phase of the system's security lifecycle.

Concept tested: NIST RMF Monitor step description

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Risk Management Framework#NIST RMF#RMF Step 6#System Authorization

Community Discussion

No community discussion yet for this question.

Full CGRC Practice