nerdexam
(ISC)2

CGRC · Question #581

When attempting to categorize a system which two RMF starting point inputs should be accounted for and are critical input to Categorization? Response:

The correct answer is A. Architectural descriptions and organizational inputs. When categorizing a system in RMF, critical inputs include architectural descriptions, which detail the system's structure and components, and organizational inputs, which provide context on the system's mission and business functions. These inputs are vital for accurately…

Scope of the System

Question

When attempting to categorize a system which two RMF starting point inputs should be accounted for and are critical input to Categorization? Response:

Options

  • AArchitectural descriptions and organizational inputs
  • BFederal laws and organizational policies
  • CFederal laws and Office of Management and Budget (OMB) policies
  • DFederal Information Security Management Act (FISMA) and the Privacy Act

How the community answered

(26 responses)
  • A
    88% (23)
  • C
    8% (2)
  • D
    4% (1)

Why each option

When categorizing a system in RMF, critical inputs include architectural descriptions, which detail the system's structure and components, and organizational inputs, which provide context on the system's mission and business functions. These inputs are vital for accurately determining the system's security impact level.

AArchitectural descriptions and organizational inputsCorrect

According to NIST RMF guidance, system categorization (Step 1) requires understanding the system's purpose and the data it processes. Architectural descriptions provide details on system boundaries, components, and data flows, while organizational inputs define the system's mission, business functions, and the types of information it handles, making both critical for assigning impact levels.

BFederal laws and organizational policies

While federal laws and organizational policies are important for RMF implementation, they typically guide the categorization process and determine requirements, rather than being direct inputs to categorize a specific system's function and data.

CFederal laws and Office of Management and Budget (OMB) policies

Federal laws and OMB policies provide high-level directives and requirements, but are not the specific, detailed inputs directly used to describe a system's characteristics for categorization.

DFederal Information Security Management Act (FISMA) and the Privacy Act

FISMA and the Privacy Act are foundational laws that establish requirements, but they are not direct inputs describing a particular system's architecture or organizational context for categorization.

Concept tested: RMF Step 1 Categorization inputs

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#RMF#System Categorization#Inputs#NIST RMF

Community Discussion

No community discussion yet for this question.

Full CGRC Practice