nerdexam
(ISC)2

CGRC · Question #537

During which RMF step is the system security plan (SP) approved? Response:

The correct answer is A. RMF Step 2, Select Security Controls. In the Risk Management Framework (RMF), the System Security Plan (SSP), which documents the system's security controls, is approved during the second step of the process. This approval ensures that the selected controls and overall security approach are formally accepted before i

Selection and Approval of Framework, Security, and Privacy Controls

Question

During which RMF step is the system security plan (SP) approved? Response:

Options

  • ARMF Step 2, Select Security Controls
  • BRMF Step 1 Categorize Information System
  • CRMF Step 3 Implement Security Controls
  • DRMF Step 5 Authorize Information System

How the community answered

(24 responses)
  • A
    88% (21)
  • C
    8% (2)
  • D
    4% (1)

Why each option

In the Risk Management Framework (RMF), the System Security Plan (SSP), which documents the system's security controls, is approved during the second step of the process. This approval ensures that the selected controls and overall security approach are formally accepted before implementation.

ARMF Step 2, Select Security ControlsCorrect

The system security plan (SSP) is developed in RMF Step 2, "Select Security Controls," and is formally approved by the authorizing official or designated representative within this same step.

BRMF Step 1 Categorize Information System

RMF Step 1, "Categorize Information System," focuses on system categorization and impact levels, not the approval of the system security plan.

CRMF Step 3 Implement Security Controls

RMF Step 3, "Implement Security Controls," is where the controls outlined in the approved SSP are put into practice, not where the plan itself is approved.

DRMF Step 5 Authorize Information System

RMF Step 5, "Authorize Information System," involves the authorizing official making a final risk-based decision about operating the system, which relies on the SSP having been previously approved and controls assessed.

Concept tested: RMF System Security Plan approval step

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#RMF#System Security Plan (SSP)#Control Selection#NIST SP 800-37

Community Discussion

No community discussion yet for this question.

Full CGRC Practice