CGRC · Question #574
The person primarily responsible for RMF Step 1, Categorization. Response:
The correct answer is A. Information System Owner. The Information System Owner is primarily responsible for RMF Step 1, Categorization, which involves defining the system's mission, business functions, and the types of information processed. This initial step sets the foundation for determining the system's security impact…
Question
The person primarily responsible for RMF Step 1, Categorization. Response:
Options
- AInformation System Owner
- BSystem Development Life-Cycle
- CRisk Management Framework
- DPlan of Action and Milestones
How the community answered
(70 responses)- A90% (63)
- B1% (1)
- C3% (2)
- D6% (4)
Why each option
The Information System Owner is primarily responsible for RMF Step 1, Categorization, which involves defining the system's mission, business functions, and the types of information processed. This initial step sets the foundation for determining the system's security impact level.
The Information System Owner holds the primary responsibility for RMF Step 1, Categorization, as they are most knowledgeable about the system's purpose, the data it processes, and its mission-criticality, which are all essential for assigning appropriate security categories. This role is accountable for the system's development, procurement, integration, modification, and operation.
System Development Life-Cycle (SDLC) is a process, not a person, responsible for categorization.
Risk Management Framework (RMF) is a process, not a person, responsible for categorization.
Plan of Action and Milestones (POA&M) is a document used to track and manage security weaknesses, not a person responsible for categorization.
Concept tested: RMF Step 1 Categorization responsibility
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.