CGRC · Question #90
In which of the RMF phases (task 3) is the conduct remediation actions based on the results of ongoing monitoring activities, assessment of risk and outstanding items in the POA&M and milestones…
The correct answer is A. RMF Step 6, Monitor. Remediation actions based on ongoing monitoring, risk assessment, and outstanding items in the Plan of Action and Milestones (POA&M) are conducted during the Monitor phase (RMF Step 6).
Question
In which of the RMF phases (task 3) is the conduct remediation actions based on the results of ongoing monitoring activities, assessment of risk and outstanding items in the POA&M and milestones. Response:
Options
- ARMF Step 6, Monitor
- BRMF Step 6, Authorize
- CRMF Step 6, Implement
- DRMF Step 5, Authorize
How the community answered
(27 responses)- A96% (26)
- C4% (1)
Why each option
Remediation actions based on ongoing monitoring, risk assessment, and outstanding items in the Plan of Action and Milestones (POA&M) are conducted during the Monitor phase (RMF Step 6).
The Monitor step (Step 6) of the NIST Risk Management Framework (RMF) involves continuous monitoring of security controls to ensure they remain effective over time. This phase includes conducting ongoing assessments, performing impact analyses, and initiating remediation actions for identified deficiencies, risks, and items in the Plan of Action and Milestones (POA&M).
The Authorize step (Step 5) is where an Authorizing Official makes a risk-based decision to authorize a system's operation, not where remediation actions are conducted.
The Implement step (Step 3) is where security controls are initially put into place, not where ongoing remediation based on monitoring occurs.
RMF Step 5 is Authorize, which is incorrect as explained above; also, remediation happens during monitoring.
Concept tested: NIST RMF - Monitor step activities
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.