CGRC · Question #708
Which publication primarily targets activities in Tier 3 of Risk Management approach/pyramid? Response:
The correct answer is A. NIST SP 800-37. NIST Special Publication 800-37, "Guide for Applying the Risk Management Framework (RMF) to Federal Information Systems and Organizations," primarily guides activities at Tier 3, the system level.
Question
Which publication primarily targets activities in Tier 3 of Risk Management approach/pyramid? Response:
Options
- ANIST SP 800-37
- BNIST SP 800-38
- CNIST SP 800-53
- DNIST SP 800-53A
How the community answered
(48 responses)- A88% (42)
- B2% (1)
- C8% (4)
- D2% (1)
Why each option
NIST Special Publication 800-37, "Guide for Applying the Risk Management Framework (RMF) to Federal Information Systems and Organizations," primarily guides activities at Tier 3, the system level.
NIST SP 800-37 provides the Risk Management Framework (RMF) which details the processes for managing security and privacy risk for individual information systems. This focus on system-level risk management directly corresponds to Tier 3 activities in the NIST risk management approach.
NIST SP 800-38 is a recommendation for block cipher modes of operation and is not related to the tiers of risk management.
NIST SP 800-53 specifies the catalog of security and privacy controls, which are implemented at Tier 3, but SP 800-37 describes the framework for *applying* those controls.
NIST SP 800-53A provides guidance on assessing the security and privacy controls (from 800-53) and, while a Tier 3 activity, SP 800-37 is the overarching guide for the RMF application.
Concept tested: NIST RMF Tiers and associated publications
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev2/final
Topics
Community Discussion
No community discussion yet for this question.