nerdexam
(ISC)2

CGRC · Question #708

Which publication primarily targets activities in Tier 3 of Risk Management approach/pyramid? Response:

The correct answer is A. NIST SP 800-37. NIST Special Publication 800-37, "Guide for Applying the Risk Management Framework (RMF) to Federal Information Systems and Organizations," primarily guides activities at Tier 3, the system level.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which publication primarily targets activities in Tier 3 of Risk Management approach/pyramid? Response:

Options

  • ANIST SP 800-37
  • BNIST SP 800-38
  • CNIST SP 800-53
  • DNIST SP 800-53A

How the community answered

(48 responses)
  • A
    88% (42)
  • B
    2% (1)
  • C
    8% (4)
  • D
    2% (1)

Why each option

NIST Special Publication 800-37, "Guide for Applying the Risk Management Framework (RMF) to Federal Information Systems and Organizations," primarily guides activities at Tier 3, the system level.

ANIST SP 800-37Correct

NIST SP 800-37 provides the Risk Management Framework (RMF) which details the processes for managing security and privacy risk for individual information systems. This focus on system-level risk management directly corresponds to Tier 3 activities in the NIST risk management approach.

BNIST SP 800-38

NIST SP 800-38 is a recommendation for block cipher modes of operation and is not related to the tiers of risk management.

CNIST SP 800-53

NIST SP 800-53 specifies the catalog of security and privacy controls, which are implemented at Tier 3, but SP 800-37 describes the framework for *applying* those controls.

DNIST SP 800-53A

NIST SP 800-53A provides guidance on assessing the security and privacy controls (from 800-53) and, while a Tier 3 activity, SP 800-37 is the overarching guide for the RMF application.

Concept tested: NIST RMF Tiers and associated publications

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev2/final

Topics

#NIST RMF#Risk Management Tiers#NIST SP 800-37#Compliance Guidance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice