CGRC · Question #71
NIST SP 800-37 provides guidance for applying RMF to all of which type of information systems for design, development, implementation, operation, maintenance and development? Response:
The correct answer is A. Federal. NIST SP 800-37 provides the Risk Management Framework (RMF) guidance primarily for federal information systems. The RMF process is designed to ensure that security is integrated into the system's lifecycle for these government systems.
Question
NIST SP 800-37 provides guidance for applying RMF to all of which type of information systems for design, development, implementation, operation, maintenance and development? Response:
Options
- AFederal
- BDetach
- CSell
- DForfeit
How the community answered
(36 responses)- A92% (33)
- B3% (1)
- C3% (1)
- D3% (1)
Why each option
NIST SP 800-37 provides the Risk Management Framework (RMF) guidance primarily for federal information systems. The RMF process is designed to ensure that security is integrated into the system's lifecycle for these government systems.
NIST SP 800-37, "Guide for Applying the Risk Management Framework to Federal Information Systems," explicitly states its scope is federal information systems. This framework helps federal agencies manage security and privacy risks for their systems and data.
"Detach" is not a recognized category of information system for which NIST SP 800-37 provides guidance.
"Sell" is not a recognized category of information system for which NIST SP 800-37 provides guidance.
"Forfeit" is not a recognized category of information system for which NIST SP 800-37 provides guidance.
Concept tested: NIST SP 800-37 scope and applicability
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.