CGRC · Question #538
According to NIST SP 800-37 Rev 2, step 6 of the risk management framework can be described as: Response:
The correct answer is C. The authorization phase of the system authorization plan. According to NIST SP 800-37 Rev. 2, Step 6 of the Risk Management Framework is explicitly defined as the "Authorize Information System" phase. This step involves the Authorizing Official making a final, risk-based decision to permit the system to operate.
Question
According to NIST SP 800-37 Rev 2, step 6 of the risk management framework can be described as:
Response:
Options
- AThe certification phase of the system authorization plan
- BThe pre-certification phase of the system authorization plan
- CThe authorization phase of the system authorization plan
- DThe post-authorization phase of the system authorization plan
How the community answered
(19 responses)- A5% (1)
- B5% (1)
- C89% (17)
Why each option
According to NIST SP 800-37 Rev. 2, Step 6 of the Risk Management Framework is explicitly defined as the "Authorize Information System" phase. This step involves the Authorizing Official making a final, risk-based decision to permit the system to operate.
While "certification" was part of the older C&A process, Step 6 in RMF Rev. 2 is specifically the authorization decision, not a certification phase.
The pre-certification phase would precede the authorization decision, typically encompassing activities like control assessment (Step 4) and monitoring (Step 5).
NIST SP 800-37 Rev. 2 clearly defines Step 6 as "Authorize Information System," where the authorizing official makes a decision to authorize the system's operation based on the overall risk.
The post-authorization phase would relate to continuous monitoring (Step 7) after the authorization decision has been made.
Concept tested: RMF Step 6 - Authorize Information System
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.