CGRC · Question #38
Prepare, Categorize, select, and implement are steps or phases of the risk management framework which can be described as Response:
The correct answer is B. The pre-certification phase of the system authorization plan. The "Prepare, Categorize, Select, and Implement" steps are the initial phases of the NIST Risk Management Framework (RMF), which precede the formal certification (assessment) and authorization decision.
Question
Prepare, Categorize, select, and implement are steps or phases of the risk management framework which can be described as Response:
Options
- AThe certification phase of the system authorization plan
- BThe pre-certification phase of the system authorization plan
- CThe authorization phase of the system authorization plan
- DThe post-authorization phase of the system authorization plan
How the community answered
(20 responses)- B90% (18)
- C5% (1)
- D5% (1)
Why each option
The "Prepare, Categorize, Select, and Implement" steps are the initial phases of the NIST Risk Management Framework (RMF), which precede the formal certification (assessment) and authorization decision.
The certification phase (Assess) occurs after Prepare, Categorize, Select, and Implement, focusing on evaluating the implemented controls.
In the NIST Risk Management Framework (RMF), the Prepare, Categorize, Select, and Implement steps are foundational activities that occur before the formal assessment (certification) and subsequent authorization decision. These steps establish the security foundation for the system.
The authorization phase (Authorize) is the decision point made by a senior official, which occurs after the assessment (certification) of controls.
The post-authorization phase (Monitor) occurs after the system has been authorized, focusing on continuous monitoring of controls.
Concept tested: NIST RMF phases and their sequence
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.