CGRC · Question #470
Which of the following are phases of the National Institute of Standards and Technology (NIST) Risk Management Framework? Response:
The correct answer is A. Categorize, select, implement, authorize. The National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) includes distinct phases such as Categorize, Select, Implement, and Authorize.
Question
Which of the following are phases of the National Institute of Standards and Technology (NIST) Risk Management Framework? Response:
Options
- ACategorize, select, implement, authorize
- BAssess, certify, accredit, manage
- CPrepare, execute, authorize, monitor
- DAssess, mitigate, authorize, monitor
How the community answered
(34 responses)- A88% (30)
- B3% (1)
- C6% (2)
- D3% (1)
Why each option
The National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) includes distinct phases such as Categorize, Select, Implement, and Authorize.
Categorize, Select, Implement, and Authorize are all official and sequential steps (Steps 2, 3, 4, and 6) within the seven-step NIST Risk Management Framework.
Certify and Accredit are older terms from the Certification & Accreditation (C&A) process that were largely superseded by the RMF's 'Authorize' step and are not current RMF phases.
Execute is not a formal phase within the NIST RMF; the official phases are Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.
Mitigate is a risk response strategy that occurs during the Implement phase but is not a distinct RMF phase itself, and the combination listed does not represent the official RMF phases.
Concept tested: NIST Risk Management Framework (RMF) phases
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.