CGRC · Question #58
As indicated in NIST SP 800-37, and NIST SP 800-53 the RMF provides architectural description inputs to the risk management strategy, including mission/business processes, FEA reference models, segmen
The correct answer is C. Laws, directives and policy guidance. The Risk Management Framework (RMF) considers various architectural inputs for risk management strategy, including mission processes, reference models, system architectures, and foundational governance documents. Laws, directives, and policy guidance are critical for establishing
Question
As indicated in NIST SP 800-37, and NIST SP 800-53 the RMF provides architectural description inputs to the risk management strategy, including mission/business processes, FEA reference models, segment and solution architecture and:
Response:
Options
- AInformation security requirements
- BInformation system boundaries
- CLaws, directives and policy guidance
- DStrategic goals and objectives
How the community answered
(36 responses)- A3% (1)
- B3% (1)
- C89% (32)
- D6% (2)
Why each option
The Risk Management Framework (RMF) considers various architectural inputs for risk management strategy, including mission processes, reference models, system architectures, and foundational governance documents. Laws, directives, and policy guidance are critical for establishing the strategic context.
Information security requirements are outcomes or derivations from these inputs, not core architectural description inputs themselves for the risk management strategy.
Information system boundaries are part of defining a system, but laws, directives, and policy guidance represent a broader, foundational set of inputs guiding the overall RMF strategy.
As indicated in NIST SP 800-37, the RMF utilizes architectural description inputs such as mission/business processes, FEA reference models, segment and solution architecture, and importantly, relevant laws, directives, and policy guidance to inform the risk management strategy.
Strategic goals and objectives are foundational, but 'laws, directives and policy guidance' are specifically highlighted as comprehensive governance inputs to the architectural description within the RMF context.
Concept tested: RMF architectural inputs
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.