nerdexam
(ISC)2

CGRC · Question #653

According to NIST SP 800-37 Rev 2, step 5 of the risk management framework can be described as: Response:

The correct answer is A. The certification phase of the system authorization plan. According to NIST SP 800-37 Rev 2, Step 5 of the Risk Management Framework is the "Authorize" phase, which includes the certification activities leading to system authorization.

Assessment/Audit of Security and Privacy Controls

Question

According to NIST SP 800-37 Rev 2, step 5 of the risk management framework can be described as:

Response:

Options

  • AThe certification phase of the system authorization plan
  • BThe pre-certification phase of the system authorization plan
  • CThe authorization phase of the system authorization plan
  • DThe post-authorization phase of the system authorization plan

How the community answered

(47 responses)
  • A
    91% (43)
  • C
    2% (1)
  • D
    6% (3)

Why each option

According to NIST SP 800-37 Rev 2, Step 5 of the Risk Management Framework is the "Authorize" phase, which includes the certification activities leading to system authorization.

AThe certification phase of the system authorization planCorrect

NIST SP 800-37 Rev 2 defines Step 5 as 'Authorize,' and within this step, the certification phase involves the assessment of security controls and documentation that supports the authorizing official's decision to authorize the system's operation.

BThe pre-certification phase of the system authorization plan

The pre-certification phase would typically occur during the 'Assess' step (Step 4), where security controls are evaluated before authorization is sought.

CThe authorization phase of the system authorization plan

While 'authorization' is the name of Step 5, 'the certification phase' more accurately describes a critical set of activities and documentation required within that step to enable the authorization decision.

DThe post-authorization phase of the system authorization plan

The post-authorization phase is associated with Step 6 ('Monitor'), where system security posture is continuously monitored after authorization is granted.

Concept tested: NIST RMF Step 5 - Authorize

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#NIST RMF#RMF Assess Step#System Authorization#Certification

Community Discussion

No community discussion yet for this question.

Full CGRC Practice