CGRC · Question #66
A fundamental of Risk Management per NIST SP 800-37 is the integration of information security requirements into an organization's what? Response:
The correct answer is A. Software Development Life-Cycle. NIST SP 800-37 emphasizes integrating information security requirements into the organization's System Development Life Cycle (often referred to as Software Development Life Cycle for applications) as a fundamental part of risk management.
Question
A fundamental of Risk Management per NIST SP 800-37 is the integration of information security requirements into an organization's what? Response:
Options
- ASoftware Development Life-Cycle
- BRisk Management Framework
- CNational Institute of Standards and Technology
- DChief Information Officer
How the community answered
(57 responses)- A91% (52)
- B5% (3)
- C2% (1)
- D2% (1)
Why each option
NIST SP 800-37 emphasizes integrating information security requirements into the organization's System Development Life Cycle (often referred to as Software Development Life Cycle for applications) as a fundamental part of risk management.
NIST SP 800-37, "Guide for Applying the Risk Management Framework to Federal Information Systems," highlights the importance of integrating security throughout the System Development Life Cycle (SDLC), which encompasses software development. By baking security into each phase of the SDLC, organizations can identify and mitigate risks early, reducing overall system vulnerabilities.
The Risk Management Framework (RMF) itself is the process described in NIST SP 800-37, not the organizational component into which security requirements are integrated.
The National Institute of Standards and Technology (NIST) is the organization that publishes the standards, not an organizational component for integration.
The Chief Information Officer (CIO) is an executive role, responsible for IT strategy, but not the framework or process into which security requirements are integrated.
Concept tested: NIST Risk Management Framework (RMF) and SDLC integration
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.