CGRC · Question #494
In which of the following Risk Management Framework (RMF) phases is a risk profile created for threats? Response:
The correct answer is C. Phase 2. Within the NIST Risk Management Framework (RMF), the risk profile, including the identification and analysis of threats, is developed in Phase 2, the Categorize phase. This phase establishes the system's risk appetite and high-level risk profile.
Question
In which of the following Risk Management Framework (RMF) phases is a risk profile created for threats? Response:
Options
- APhase 3
- BPhase 1
- CPhase 2
- DPhase 0
How the community answered
(36 responses)- A3% (1)
- B6% (2)
- C89% (32)
- D3% (1)
Why each option
Within the NIST Risk Management Framework (RMF), the risk profile, including the identification and analysis of threats, is developed in Phase 2, the Categorize phase. This phase establishes the system's risk appetite and high-level risk profile.
Phase 3 is "Select Security Controls," where controls are chosen based on the categorization, not where the risk profile is primarily created.
Phase 1 is "Prepare," which involves preparation activities before system categorization and risk profile creation.
In NIST RMF Step 2, the "Categorize System" phase, organizations establish the initial risk profile of the system based on its mission, business processes, and the types of information it processes. This involves identifying potential threats and vulnerabilities to begin forming a comprehensive risk picture.
Phase 0 is not a standard RMF phase; RMF typically consists of 7 steps or phases (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor).
Concept tested: NIST RMF Categorize Phase, Risk Profile Creation
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.