nerdexam
(ISC)2

CGRC · Question #586

The Risk Management Framwork (RMF) provides an organized approach for organization-wide risk management. What are the tiers of the organization-wide perspective? Response:

The correct answer is D. Organization, mission/business process, and system. The RMF's organization-wide perspective for risk management is structured across three tiers: the organization itself, its mission and business processes, and individual information systems.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The Risk Management Framwork (RMF) provides an organized approach for organization-wide risk management. What are the tiers of the organization-wide perspective? Response:

Options

  • AThe C-suit level, The Authorization level, and the system level
  • BOrganizational level, common control level, and system level
  • CLevel one, two, and three
  • DOrganization, mission/business process, and system

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    4% (1)
  • D
    86% (24)

Why each option

The RMF's organization-wide perspective for risk management is structured across three tiers: the organization itself, its mission and business processes, and individual information systems.

AThe C-suit level, The Authorization level, and the system level

While C-suite, authorization, and system levels involve RMF, these are not the formally defined tiers of the organization-wide perspective.

BOrganizational level, common control level, and system level

'Common control level' is a concept related to control implementation but not one of the three foundational RMF tiers.

CLevel one, two, and three

'Level one, two, and three' are generic terms and do not correspond to the specific RMF tiers.

DOrganization, mission/business process, and systemCorrect

The Risk Management Framework (RMF), as defined by NIST, organizes risk management activities into three distinct tiers: the Organization (Tier 1), the Mission/Business Process (Tier 2), and the Information System (Tier 3). These tiers provide a hierarchical approach to managing risk from strategic organizational goals down to specific system implementations.

Concept tested: NIST RMF risk management tiers

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Risk Management Framework (RMF)#NIST RMF Tiers#Organization-wide Risk Management

Community Discussion

No community discussion yet for this question.

Full CGRC Practice