CGRC · Question #394
What publication provides a structured process (RMF) to fully integrate information security and risk management activities into the SDLC in a disciplined fashion? Response:
The correct answer is A. NIST SP 800-37, Revision 1. NIST SP 800-37 provides the structured process (RMF) for integrating information security and risk management activities into the System Development Life Cycle (SDLC).
Question
What publication provides a structured process (RMF) to fully integrate information security and risk management activities into the SDLC in a disciplined fashion? Response:
Options
- ANIST SP 800-37, Revision 1
- BNIST SP 800-40, Revision 1
- CNIST SP 800-37, Revision 2
- DNIST SP 800-60, Revision 1
How the community answered
(30 responses)- A93% (28)
- C3% (1)
- D3% (1)
Why each option
NIST SP 800-37 provides the structured process (RMF) for integrating information security and risk management activities into the System Development Life Cycle (SDLC).
NIST SP 800-37, Revision 1, titled 'Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach,' established the RMF process and its integration into the SDLC. While Revision 2 is the most current, Revision 1 was instrumental in defining this structured approach.
NIST SP 800-40 focuses on continuous monitoring for information security, not the overall RMF and SDLC integration.
While NIST SP 800-37, Revision 2, is the current version, Revision 1 was the key publication that initially outlined this structured process in detail.
NIST SP 800-60 focuses on mapping information types to security categories, not the RMF or SDLC integration.
Concept tested: NIST SP 800-37 and RMF integration into SDLC
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-37r1.pdf
Topics
Community Discussion
No community discussion yet for this question.