CGRC · Question #94
The registration of the system directly follows which Risk Management Framework (RMF) task? Response:
The correct answer is B. Describe the system. In the NIST Risk Management Framework (RMF), the formal registration of an information system occurs immediately after the system's characteristics and boundaries have been described.
Question
The registration of the system directly follows which Risk Management Framework (RMF) task? Response:
Options
- ACategorize the system
- BDescribe the system
- CReview and approve the system security plan
- DSelect security controls
How the community answered
(36 responses)- A3% (1)
- B89% (32)
- C6% (2)
- D3% (1)
Why each option
In the NIST Risk Management Framework (RMF), the formal registration of an information system occurs immediately after the system's characteristics and boundaries have been described.
Categorizing the system (Step 1, Prepare) involves assigning impact levels, which generally occurs before or in conjunction with describing the system, but registration isn't directly *after* categorization.
In the NIST Risk Management Framework (RMF), the 'Describe System' task involves documenting the system's characteristics, including its boundaries, architecture, and data flows, which is a prerequisite for formal registration within the organization's inventory. Registration is an administrative step that formalizes the system's existence within the RMF process after its basic description is complete, both occurring within the 'Prepare' step.
Review and approval of the system security plan (Step 4, part of Authorize) happens much later in the RMF process, after controls have been implemented and assessed.
Selecting security controls (Step 2) happens after the system is categorized and described, preceding implementation and assessment.
Concept tested: NIST RMF process - Describe System
Source: https://csrc.nist.gov/projects/risk-management-framework/rmf-steps
Topics
Community Discussion
No community discussion yet for this question.