CGRC · Question #653
According to NIST SP 800-37 Rev 2, step 5 of the risk management framework can be described as: Response:
The correct answer is A. The certification phase of the system authorization plan. According to NIST SP 800-37 Rev 2, Step 5 of the Risk Management Framework is the "Authorize" phase, which includes the certification activities leading to system authorization.
Question
According to NIST SP 800-37 Rev 2, step 5 of the risk management framework can be described as:
Response:
Options
- AThe certification phase of the system authorization plan
- BThe pre-certification phase of the system authorization plan
- CThe authorization phase of the system authorization plan
- DThe post-authorization phase of the system authorization plan
How the community answered
(47 responses)- A91% (43)
- C2% (1)
- D6% (3)
Why each option
According to NIST SP 800-37 Rev 2, Step 5 of the Risk Management Framework is the "Authorize" phase, which includes the certification activities leading to system authorization.
NIST SP 800-37 Rev 2 defines Step 5 as 'Authorize,' and within this step, the certification phase involves the assessment of security controls and documentation that supports the authorizing official's decision to authorize the system's operation.
The pre-certification phase would typically occur during the 'Assess' step (Step 4), where security controls are evaluated before authorization is sought.
While 'authorization' is the name of Step 5, 'the certification phase' more accurately describes a critical set of activities and documentation required within that step to enable the authorization decision.
The post-authorization phase is associated with Step 6 ('Monitor'), where system security posture is continuously monitored after authorization is granted.
Concept tested: NIST RMF Step 5 - Authorize
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.