nerdexam
(ISC)2

CGRC · Question #494

In which of the following Risk Management Framework (RMF) phases is a risk profile created for threats? Response:

The correct answer is C. Phase 2. Within the NIST Risk Management Framework (RMF), the risk profile, including the identification and analysis of threats, is developed in Phase 2, the Categorize phase. This phase establishes the system's risk appetite and high-level risk profile.

Selection and Approval of Framework, Security, and Privacy Controls

Question

In which of the following Risk Management Framework (RMF) phases is a risk profile created for threats? Response:

Options

  • APhase 3
  • BPhase 1
  • CPhase 2
  • DPhase 0

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    89% (32)
  • D
    3% (1)

Why each option

Within the NIST Risk Management Framework (RMF), the risk profile, including the identification and analysis of threats, is developed in Phase 2, the Categorize phase. This phase establishes the system's risk appetite and high-level risk profile.

APhase 3

Phase 3 is "Select Security Controls," where controls are chosen based on the categorization, not where the risk profile is primarily created.

BPhase 1

Phase 1 is "Prepare," which involves preparation activities before system categorization and risk profile creation.

CPhase 2Correct

In NIST RMF Step 2, the "Categorize System" phase, organizations establish the initial risk profile of the system based on its mission, business processes, and the types of information it processes. This involves identifying potential threats and vulnerabilities to begin forming a comprehensive risk picture.

DPhase 0

Phase 0 is not a standard RMF phase; RMF typically consists of 7 steps or phases (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor).

Concept tested: NIST RMF Categorize Phase, Risk Profile Creation

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#RMF Phases#Risk Profile#Threat Management#Control Selection

Community Discussion

No community discussion yet for this question.

Full CGRC Practice