nerdexam
(ISC)2

CGRC · Question #538

According to NIST SP 800-37 Rev 2, step 6 of the risk management framework can be described as: Response:

The correct answer is C. The authorization phase of the system authorization plan. According to NIST SP 800-37 Rev. 2, Step 6 of the Risk Management Framework is explicitly defined as the "Authorize Information System" phase. This step involves the Authorizing Official making a final, risk-based decision to permit the system to operate.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

According to NIST SP 800-37 Rev 2, step 6 of the risk management framework can be described as:

Response:

Options

  • AThe certification phase of the system authorization plan
  • BThe pre-certification phase of the system authorization plan
  • CThe authorization phase of the system authorization plan
  • DThe post-authorization phase of the system authorization plan

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    89% (17)

Why each option

According to NIST SP 800-37 Rev. 2, Step 6 of the Risk Management Framework is explicitly defined as the "Authorize Information System" phase. This step involves the Authorizing Official making a final, risk-based decision to permit the system to operate.

AThe certification phase of the system authorization plan

While "certification" was part of the older C&A process, Step 6 in RMF Rev. 2 is specifically the authorization decision, not a certification phase.

BThe pre-certification phase of the system authorization plan

The pre-certification phase would precede the authorization decision, typically encompassing activities like control assessment (Step 4) and monitoring (Step 5).

CThe authorization phase of the system authorization planCorrect

NIST SP 800-37 Rev. 2 clearly defines Step 6 as "Authorize Information System," where the authorizing official makes a decision to authorize the system's operation based on the overall risk.

DThe post-authorization phase of the system authorization plan

The post-authorization phase would relate to continuous monitoring (Step 7) after the authorization decision has been made.

Concept tested: RMF Step 6 - Authorize Information System

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST RMF#Risk Management Framework#Authorization#NIST SP 800-37 Rev 2

Community Discussion

No community discussion yet for this question.

Full CGRC Practice