nerdexam
(ISC)2

CGRC · Question #394

What publication provides a structured process (RMF) to fully integrate information security and risk management activities into the SDLC in a disciplined fashion? Response:

The correct answer is A. NIST SP 800-37, Revision 1. NIST SP 800-37 provides the structured process (RMF) for integrating information security and risk management activities into the System Development Life Cycle (SDLC).

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What publication provides a structured process (RMF) to fully integrate information security and risk management activities into the SDLC in a disciplined fashion? Response:

Options

  • ANIST SP 800-37, Revision 1
  • BNIST SP 800-40, Revision 1
  • CNIST SP 800-37, Revision 2
  • DNIST SP 800-60, Revision 1

How the community answered

(30 responses)
  • A
    93% (28)
  • C
    3% (1)
  • D
    3% (1)

Why each option

NIST SP 800-37 provides the structured process (RMF) for integrating information security and risk management activities into the System Development Life Cycle (SDLC).

ANIST SP 800-37, Revision 1Correct

NIST SP 800-37, Revision 1, titled 'Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach,' established the RMF process and its integration into the SDLC. While Revision 2 is the most current, Revision 1 was instrumental in defining this structured approach.

BNIST SP 800-40, Revision 1

NIST SP 800-40 focuses on continuous monitoring for information security, not the overall RMF and SDLC integration.

CNIST SP 800-37, Revision 2

While NIST SP 800-37, Revision 2, is the current version, Revision 1 was the key publication that initially outlined this structured process in detail.

DNIST SP 800-60, Revision 1

NIST SP 800-60 focuses on mapping information types to security categories, not the RMF or SDLC integration.

Concept tested: NIST SP 800-37 and RMF integration into SDLC

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-37r1.pdf

Topics

#RMF#NIST SP 800-37#SDLC Integration#Information Security

Community Discussion

No community discussion yet for this question.

Full CGRC Practice