nerdexam
(ISC)2

CGRC · Question #686

When attempting to categorize a system, which two RMF starting point inputs should be accounted for? Response:

The correct answer is C. Architecture descriptions and organizational inputs. When categorizing a system within the Risk Management Framework (RMF), the initial inputs should include the system's architecture descriptions to understand its scope and components, alongside organizational inputs such as policies and mission objectives.

Scope of the System

Question

When attempting to categorize a system, which two RMF starting point inputs should be accounted for? Response:

Options

  • AFederal laws and organizational policies
  • BFederal laws and OMB policies
  • CArchitecture descriptions and organizational inputs
  • DFISMA and the Privacy Act

How the community answered

(30 responses)
  • B
    7% (2)
  • C
    90% (27)
  • D
    3% (1)

Why each option

When categorizing a system within the Risk Management Framework (RMF), the initial inputs should include the system's architecture descriptions to understand its scope and components, alongside organizational inputs such as policies and mission objectives.

AFederal laws and organizational policies

While federal laws and organizational policies are important throughout the RMF, 'architecture descriptions' and broader 'organizational inputs' are more direct starting point inputs for the categorization process itself.

BFederal laws and OMB policies

Federal laws and OMB policies are high-level drivers but not the granular, direct inputs for categorizing a specific system in the same way as architectural details and specific organizational mission needs.

CArchitecture descriptions and organizational inputsCorrect

When initiating the categorization of an information system within the RMF, it is crucial to account for the system's architecture descriptions to understand its components, interconnections, and boundaries. Additionally, organizational inputs, such as mission requirements, policies, and risk tolerance, are essential to properly define the impact levels for confidentiality, integrity, and availability.

DFISMA and the Privacy Act

FISMA and the Privacy Act are foundational federal laws that drive the RMF but are not the specific inputs used to categorize a system; rather, they establish the requirement for categorization.

Concept tested: RMF System Categorization Inputs

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev2/final

Topics

#RMF#System Categorization#Inputs#NIST SP 800-37

Community Discussion

No community discussion yet for this question.

Full CGRC Practice