CGRC · Question #581
When attempting to categorize a system which two RMF starting point inputs should be accounted for and are critical input to Categorization? Response:
The correct answer is A. Architectural descriptions and organizational inputs. When categorizing a system in RMF, critical inputs include architectural descriptions, which detail the system's structure and components, and organizational inputs, which provide context on the system's mission and business functions. These inputs are vital for accurately…
Question
When attempting to categorize a system which two RMF starting point inputs should be accounted for and are critical input to Categorization? Response:
Options
- AArchitectural descriptions and organizational inputs
- BFederal laws and organizational policies
- CFederal laws and Office of Management and Budget (OMB) policies
- DFederal Information Security Management Act (FISMA) and the Privacy Act
How the community answered
(26 responses)- A88% (23)
- C8% (2)
- D4% (1)
Why each option
When categorizing a system in RMF, critical inputs include architectural descriptions, which detail the system's structure and components, and organizational inputs, which provide context on the system's mission and business functions. These inputs are vital for accurately determining the system's security impact level.
According to NIST RMF guidance, system categorization (Step 1) requires understanding the system's purpose and the data it processes. Architectural descriptions provide details on system boundaries, components, and data flows, while organizational inputs define the system's mission, business functions, and the types of information it handles, making both critical for assigning impact levels.
While federal laws and organizational policies are important for RMF implementation, they typically guide the categorization process and determine requirements, rather than being direct inputs to categorize a specific system's function and data.
Federal laws and OMB policies provide high-level directives and requirements, but are not the specific, detailed inputs directly used to describe a system's characteristics for categorization.
FISMA and the Privacy Act are foundational laws that establish requirements, but they are not direct inputs describing a particular system's architecture or organizational context for categorization.
Concept tested: RMF Step 1 Categorization inputs
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.