CGRC · Question #76
In what step of the RMF process would you create the SSP? Response:
The correct answer is A. Step 1 (Categorization). The System Security Plan (SSP) is developed during Step 1 (Categorize) of the RMF process, which involves documenting how the system addresses security and privacy requirements. While the SSP evolves throughout the RMF, its initial creation and foundational information are establ
Question
In what step of the RMF process would you create the SSP? Response:
Options
- AStep 1 (Categorization)
- BStep 2 (Recommendations)
- CStep 3 (Mitigation)
- DStep 4 (Determination)
How the community answered
(43 responses)- A93% (40)
- C2% (1)
- D5% (2)
Why each option
The System Security Plan (SSP) is developed during Step 1 (Categorize) of the RMF process, which involves documenting how the system addresses security and privacy requirements. While the SSP evolves throughout the RMF, its initial creation and foundational information are established in this first step.
The System Security Plan (SSP) is typically created and initiated during Step 1 (Categorize) of the RMF process. This step involves defining the system's mission, identifying its boundaries, and categorizing its information, which forms the basis for the SSP that details how security controls will be implemented.
"Recommendations" is not a formal step in the NIST RMF.
"Mitigation" is not a formal step in the NIST RMF; controls are implemented and assessed in later steps.
"Determination" is not a formal step in the NIST RMF. The RMF steps are Categorize, Select, Implement, Assess, Authorize, and Monitor.
Concept tested: RMF Step 1 - System Security Plan (SSP) creation
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.