nerdexam
(ISC)2

CGRC · Question #624

During which Risk Management Framework (RMF) step is the system security plan initially approved? Response:

The correct answer is B. RMF Step 2 Select Security Controls. The system security plan (SSP) is initially approved during RMF Step 2, 'Select Security Controls,' after the appropriate controls are chosen for the information system. This approval confirms the agreed-upon security approach before control implementation begins.

Selection and Approval of Framework, Security, and Privacy Controls

Question

During which Risk Management Framework (RMF) step is the system security plan initially approved? Response:

Options

  • ARMF Step 1 Categorize Information System
  • BRMF Step 2 Select Security Controls
  • CRMF Step 3 Implement Security Controls
  • DRMF Step 5 Authorize Information System

How the community answered

(58 responses)
  • A
    2% (1)
  • B
    90% (52)
  • C
    5% (3)
  • D
    3% (2)

Why each option

The system security plan (SSP) is initially approved during RMF Step 2, 'Select Security Controls,' after the appropriate controls are chosen for the information system. This approval confirms the agreed-upon security approach before control implementation begins.

ARMF Step 1 Categorize Information System

RMF Step 1, 'Categorize Information System,' focuses on determining the impact level of the system and its information, not on the approval of the SSP.

BRMF Step 2 Select Security ControlsCorrect

In RMF Step 2, 'Select Security Controls,' organizations select and tailor the baseline security controls based on the system's categorization. The system security plan (SSP), which documents these chosen controls and the planned security posture, is then initially approved to ensure formal agreement and acceptance before proceeding to implement the controls.

CRMF Step 3 Implement Security Controls

RMF Step 3, 'Implement Security Controls,' involves putting the chosen security controls into practice, which occurs after the initial approval of the SSP.

DRMF Step 5 Authorize Information System

RMF Step 5, 'Authorize Information System,' is where the Authorizing Official grants a final authorization to operate the system, a much later stage than the initial approval of the SSP.

Concept tested: RMF System Security Plan approval

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#RMF Steps#System Security Plan (SSP)#Security Control Selection#SSP Approval

Community Discussion

No community discussion yet for this question.

Full CGRC Practice