nerdexam
(ISC)2

CGRC · Question #393

NIST SP 800-37 defines a 3-tiered approach to the RMF, which are? Response:

The correct answer is A. Organization, Mission/business process, Information system. NIST SP 800-37 defines a three-tiered approach to the Risk Management Framework, structuring activities across different organizational levels.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

NIST SP 800-37 defines a 3-tiered approach to the RMF, which are? Response:

Options

  • AOrganization, Mission/business process, Information system
  • BMission/business process, Information system
  • CImplement Control & Criticality/Sensitivity, Information System
  • DInformation System & Mission/business process

How the community answered

(42 responses)
  • A
    93% (39)
  • B
    5% (2)
  • C
    2% (1)

Why each option

NIST SP 800-37 defines a three-tiered approach to the Risk Management Framework, structuring activities across different organizational levels.

AOrganization, Mission/business process, Information systemCorrect

The three tiers of the NIST RMF, as defined in NIST SP 800-37, are Organization (Tier 1), Mission/Business Process (Tier 2), and Information System (Tier 3). This tiered approach ensures a comprehensive and integrated risk management strategy across all organizational levels.

BMission/business process, Information system

This choice is incomplete, missing the 'Organization' tier.

CImplement Control & Criticality/Sensitivity, Information System

This choice lists specific RMF activities or concepts rather than the defined tiers.

DInformation System & Mission/business process

This choice is incomplete, missing the 'Organization' tier.

Concept tested: NIST RMF 3-tiered approach

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST SP 800-37#Risk Management Framework (RMF)#RMF Tiers

Community Discussion

No community discussion yet for this question.

Full CGRC Practice