nerdexam
(ISC)2

CGRC · Question #66

A fundamental of Risk Management per NIST SP 800-37 is the integration of information security requirements into an organization's what? Response:

The correct answer is A. Software Development Life-Cycle. NIST SP 800-37 emphasizes integrating information security requirements into the organization's System Development Life Cycle (often referred to as Software Development Life Cycle for applications) as a fundamental part of risk management.

Implementation of Security and Privacy Controls

Question

A fundamental of Risk Management per NIST SP 800-37 is the integration of information security requirements into an organization's what? Response:

Options

  • ASoftware Development Life-Cycle
  • BRisk Management Framework
  • CNational Institute of Standards and Technology
  • DChief Information Officer

How the community answered

(57 responses)
  • A
    91% (52)
  • B
    5% (3)
  • C
    2% (1)
  • D
    2% (1)

Why each option

NIST SP 800-37 emphasizes integrating information security requirements into the organization's System Development Life Cycle (often referred to as Software Development Life Cycle for applications) as a fundamental part of risk management.

ASoftware Development Life-CycleCorrect

NIST SP 800-37, "Guide for Applying the Risk Management Framework to Federal Information Systems," highlights the importance of integrating security throughout the System Development Life Cycle (SDLC), which encompasses software development. By baking security into each phase of the SDLC, organizations can identify and mitigate risks early, reducing overall system vulnerabilities.

BRisk Management Framework

The Risk Management Framework (RMF) itself is the process described in NIST SP 800-37, not the organizational component into which security requirements are integrated.

CNational Institute of Standards and Technology

The National Institute of Standards and Technology (NIST) is the organization that publishes the standards, not an organizational component for integration.

DChief Information Officer

The Chief Information Officer (CIO) is an executive role, responsible for IT strategy, but not the framework or process into which security requirements are integrated.

Concept tested: NIST Risk Management Framework (RMF) and SDLC integration

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#NIST SP 800-37#Risk Management#Information Security Integration#SDLC

Community Discussion

No community discussion yet for this question.

Full CGRC Practice