nerdexam
(ISC)2

CGRC · Question #470

Which of the following are phases of the National Institute of Standards and Technology (NIST) Risk Management Framework? Response:

The correct answer is A. Categorize, select, implement, authorize. The National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) includes distinct phases such as Categorize, Select, Implement, and Authorize.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following are phases of the National Institute of Standards and Technology (NIST) Risk Management Framework? Response:

Options

  • ACategorize, select, implement, authorize
  • BAssess, certify, accredit, manage
  • CPrepare, execute, authorize, monitor
  • DAssess, mitigate, authorize, monitor

How the community answered

(34 responses)
  • A
    88% (30)
  • B
    3% (1)
  • C
    6% (2)
  • D
    3% (1)

Why each option

The National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) includes distinct phases such as Categorize, Select, Implement, and Authorize.

ACategorize, select, implement, authorizeCorrect

Categorize, Select, Implement, and Authorize are all official and sequential steps (Steps 2, 3, 4, and 6) within the seven-step NIST Risk Management Framework.

BAssess, certify, accredit, manage

Certify and Accredit are older terms from the Certification & Accreditation (C&A) process that were largely superseded by the RMF's 'Authorize' step and are not current RMF phases.

CPrepare, execute, authorize, monitor

Execute is not a formal phase within the NIST RMF; the official phases are Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.

DAssess, mitigate, authorize, monitor

Mitigate is a risk response strategy that occurs during the Implement phase but is not a distinct RMF phase itself, and the combination listed does not represent the official RMF phases.

Concept tested: NIST Risk Management Framework (RMF) phases

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST RMF#Risk Management Framework#RMF Phases#Cybersecurity Frameworks

Community Discussion

No community discussion yet for this question.

Full CGRC Practice