CGRC · Question #586
The Risk Management Framwork (RMF) provides an organized approach for organization-wide risk management. What are the tiers of the organization-wide perspective? Response:
The correct answer is D. Organization, mission/business process, and system. The RMF's organization-wide perspective for risk management is structured across three tiers: the organization itself, its mission and business processes, and individual information systems.
Question
The Risk Management Framwork (RMF) provides an organized approach for organization-wide risk management. What are the tiers of the organization-wide perspective? Response:
Options
- AThe C-suit level, The Authorization level, and the system level
- BOrganizational level, common control level, and system level
- CLevel one, two, and three
- DOrganization, mission/business process, and system
How the community answered
(28 responses)- A4% (1)
- B7% (2)
- C4% (1)
- D86% (24)
Why each option
The RMF's organization-wide perspective for risk management is structured across three tiers: the organization itself, its mission and business processes, and individual information systems.
While C-suite, authorization, and system levels involve RMF, these are not the formally defined tiers of the organization-wide perspective.
'Common control level' is a concept related to control implementation but not one of the three foundational RMF tiers.
'Level one, two, and three' are generic terms and do not correspond to the specific RMF tiers.
The Risk Management Framework (RMF), as defined by NIST, organizes risk management activities into three distinct tiers: the Organization (Tier 1), the Mission/Business Process (Tier 2), and the Information System (Tier 3). These tiers provide a hierarchical approach to managing risk from strategic organizational goals down to specific system implementations.
Concept tested: NIST RMF risk management tiers
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.