CGRC · Question #537
During which RMF step is the system security plan (SP) approved? Response:
The correct answer is A. RMF Step 2, Select Security Controls. In the Risk Management Framework (RMF), the System Security Plan (SSP), which documents the system's security controls, is approved during the second step of the process. This approval ensures that the selected controls and overall security approach are formally accepted before i
Question
During which RMF step is the system security plan (SP) approved? Response:
Options
- ARMF Step 2, Select Security Controls
- BRMF Step 1 Categorize Information System
- CRMF Step 3 Implement Security Controls
- DRMF Step 5 Authorize Information System
How the community answered
(24 responses)- A88% (21)
- C8% (2)
- D4% (1)
Why each option
In the Risk Management Framework (RMF), the System Security Plan (SSP), which documents the system's security controls, is approved during the second step of the process. This approval ensures that the selected controls and overall security approach are formally accepted before implementation.
The system security plan (SSP) is developed in RMF Step 2, "Select Security Controls," and is formally approved by the authorizing official or designated representative within this same step.
RMF Step 1, "Categorize Information System," focuses on system categorization and impact levels, not the approval of the system security plan.
RMF Step 3, "Implement Security Controls," is where the controls outlined in the approved SSP are put into practice, not where the plan itself is approved.
RMF Step 5, "Authorize Information System," involves the authorizing official making a final risk-based decision about operating the system, which relies on the SSP having been previously approved and controls assessed.
Concept tested: RMF System Security Plan approval step
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.