nerdexam
(ISC)2

CGRC · Question #495

In which of the 6 steps of RMF is the System Boundary defined? Response:

The correct answer is A. Step 1. The system boundary is defined in Step 1 of the NIST Risk Management Framework (RMF), which is the "Prepare" step. This initial step establishes the context for the RMF process, including identifying the system and its operational scope.

Scope of the System

Question

In which of the 6 steps of RMF is the System Boundary defined? Response:

Options

  • AStep 1
  • BStep 2
  • CStep 3
  • DStep 4

How the community answered

(37 responses)
  • A
    86% (32)
  • B
    3% (1)
  • C
    3% (1)
  • D
    8% (3)

Why each option

The system boundary is defined in Step 1 of the NIST Risk Management Framework (RMF), which is the "Prepare" step. This initial step establishes the context for the RMF process, including identifying the system and its operational scope.

AStep 1Correct

In NIST RMF Step 1, "Prepare," organizations define the system boundary, which identifies the scope of the information system, including its hardware, software, firmware, and personnel, along with its physical and logical connections. This critical step sets the foundation for all subsequent RMF activities.

BStep 2

Step 2 is "Categorize System," which involves categorizing the system based on impact, assuming the boundary is already defined.

CStep 3

Step 3 is "Select Security Controls," where controls are chosen for the defined system.

DStep 4

Step 4 is "Implement Security Controls," focusing on putting controls into practice.

Concept tested: NIST RMF Prepare Step, System Boundary Definition

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#NIST RMF#RMF Steps#System Boundary#Prepare Step

Community Discussion

No community discussion yet for this question.

Full CGRC Practice