CGRC · Question #620
The tiers of the National Institute of Standards and Technology (NIST) risk management framework are Response:
The correct answer is C. organization, mission/business process, information system. The National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) is structured across three tiers: organization, mission/business process, and information system. This hierarchical approach integrates risk management at all levels of an enterprise.
Question
The tiers of the National Institute of Standards and Technology (NIST) risk management framework are Response:
Options
- Aoperational, management, system.
- Bconfidentiality, integrity, availability.
- Corganization, mission/business process, information system.
- Dprevention, detection, recovery.
How the community answered
(41 responses)- A2% (1)
- B2% (1)
- C90% (37)
- D5% (2)
Why each option
The National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) is structured across three tiers: organization, mission/business process, and information system. This hierarchical approach integrates risk management at all levels of an enterprise.
Operational, management, and system are more general categories of controls or levels of security activity, not the specific defined RMF tiers.
Confidentiality, integrity, and availability (CIA) are fundamental security objectives or principles, not the structural tiers of the RMF.
The NIST Risk Management Framework (RMF) is structured around three distinct tiers: the organizational tier, the mission/business process tier, and the information system tier. This tiered approach allows for comprehensive risk management, aligning security decisions from enterprise-wide policies down to the implementation of controls on specific systems.
Prevention, detection, and recovery are common categories of security controls or incident response phases, not the hierarchical tiers of the RMF.
Concept tested: NIST RMF tiers
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.