nerdexam
(ISC)2

CGRC · Question #620

The tiers of the National Institute of Standards and Technology (NIST) risk management framework are Response:

The correct answer is C. organization, mission/business process, information system. The National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) is structured across three tiers: organization, mission/business process, and information system. This hierarchical approach integrates risk management at all levels of an enterprise.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The tiers of the National Institute of Standards and Technology (NIST) risk management framework are Response:

Options

  • Aoperational, management, system.
  • Bconfidentiality, integrity, availability.
  • Corganization, mission/business process, information system.
  • Dprevention, detection, recovery.

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    90% (37)
  • D
    5% (2)

Why each option

The National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) is structured across three tiers: organization, mission/business process, and information system. This hierarchical approach integrates risk management at all levels of an enterprise.

Aoperational, management, system.

Operational, management, and system are more general categories of controls or levels of security activity, not the specific defined RMF tiers.

Bconfidentiality, integrity, availability.

Confidentiality, integrity, and availability (CIA) are fundamental security objectives or principles, not the structural tiers of the RMF.

Corganization, mission/business process, information system.Correct

The NIST Risk Management Framework (RMF) is structured around three distinct tiers: the organizational tier, the mission/business process tier, and the information system tier. This tiered approach allows for comprehensive risk management, aligning security decisions from enterprise-wide policies down to the implementation of controls on specific systems.

Dprevention, detection, recovery.

Prevention, detection, and recovery are common categories of security controls or incident response phases, not the hierarchical tiers of the RMF.

Concept tested: NIST RMF tiers

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST RMF#Risk Management Framework#RMF Tiers#NIST SP 800-37

Community Discussion

No community discussion yet for this question.

Full CGRC Practice