nerdexam
(ISC)2

CGRC · Question #38

Prepare, Categorize, select, and implement are steps or phases of the risk management framework which can be described as Response:

The correct answer is B. The pre-certification phase of the system authorization plan. The "Prepare, Categorize, Select, and Implement" steps are the initial phases of the NIST Risk Management Framework (RMF), which precede the formal certification (assessment) and authorization decision.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Prepare, Categorize, select, and implement are steps or phases of the risk management framework which can be described as Response:

Options

  • AThe certification phase of the system authorization plan
  • BThe pre-certification phase of the system authorization plan
  • CThe authorization phase of the system authorization plan
  • DThe post-authorization phase of the system authorization plan

How the community answered

(20 responses)
  • B
    90% (18)
  • C
    5% (1)
  • D
    5% (1)

Why each option

The "Prepare, Categorize, Select, and Implement" steps are the initial phases of the NIST Risk Management Framework (RMF), which precede the formal certification (assessment) and authorization decision.

AThe certification phase of the system authorization plan

The certification phase (Assess) occurs after Prepare, Categorize, Select, and Implement, focusing on evaluating the implemented controls.

BThe pre-certification phase of the system authorization planCorrect

In the NIST Risk Management Framework (RMF), the Prepare, Categorize, Select, and Implement steps are foundational activities that occur before the formal assessment (certification) and subsequent authorization decision. These steps establish the security foundation for the system.

CThe authorization phase of the system authorization plan

The authorization phase (Authorize) is the decision point made by a senior official, which occurs after the assessment (certification) of controls.

DThe post-authorization phase of the system authorization plan

The post-authorization phase (Monitor) occurs after the system has been authorized, focusing on continuous monitoring of controls.

Concept tested: NIST RMF phases and their sequence

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Risk Management Framework (RMF)#NIST RMF Steps#System Authorization Process#Pre-certification

Community Discussion

No community discussion yet for this question.

Full CGRC Practice