nerdexam
(ISC)2

CGRC · Question #598

What is the 3rd SDLC phase; which maps to RMF step 5 (Authorize)? Response:

The correct answer is A. Implementation. The third SDLC phase that typically maps to the RMF Authorize step is Implementation, where the system is built, controls are implemented, and the system is assessed for authorization.

Implementation of Security and Privacy Controls

Question

What is the 3rd SDLC phase; which maps to RMF step 5 (Authorize)? Response:

Options

  • AImplementation
  • BOperation
  • CRecommendation
  • DDisposition

How the community answered

(30 responses)
  • A
    93% (28)
  • C
    3% (1)
  • D
    3% (1)

Why each option

The third SDLC phase that typically maps to the RMF Authorize step is Implementation, where the system is built, controls are implemented, and the system is assessed for authorization.

AImplementationCorrect

The Implementation phase of the SDLC involves the actual building or acquisition of the system, the integration of security controls, and preparing the system for operation, which directly aligns with the activities leading up to and supporting the RMF's Authorize step.

BOperation

The Operation phase follows Authorization, focusing on ongoing use and maintenance of the system, not the initial authorization.

CRecommendation

Recommendation is not a standard, distinct phase in common SDLC models or a primary RMF step.

DDisposition

The Disposition phase is the final stage of the SDLC, involving system decommissioning, which occurs long after the authorization process.

Concept tested: SDLC Phases and RMF Step Mapping

Source: https://www.nist.gov/system/files/documents/2019/12/26/sp800-37r2-final.pdf

Topics

#SDLC Phases#RMF Steps#System Authorization#Control Implementation

Community Discussion

No community discussion yet for this question.

Full CGRC Practice