CGRC · Question #96
The initial security plan for a new application has been approved. What is the next activity in the Risk Management Framework? Response:
The correct answer is C. Implement the security controls specified in the system security plan. After the initial security plan for a new application is approved within the Risk Management Framework (RMF), the next activity is to implement the security controls specified in that plan.
Question
The initial security plan for a new application has been approved. What is the next activity in the Risk Management Framework? Response:
Options
- AAsses a selected subset of the security controls inherited by the information system.
- BAssemble the security authorization package.
- CImplement the security controls specified in the system security plan.
- DDevelop a strategy for the continuous monitoring of security control effectiveness.
How the community answered
(48 responses)- A2% (1)
- B4% (2)
- C92% (44)
- D2% (1)
Why each option
After the initial security plan for a new application is approved within the Risk Management Framework (RMF), the next activity is to implement the security controls specified in that plan.
Assessing controls (RMF Step 4) occurs after implementation, to determine if they are correctly implemented, operating as intended, and producing the desired outcome.
Assembling the security authorization package (RMF Step 5, Authorize) occurs after controls are implemented and assessed, as the package contains the evidence for the authorization decision.
According to the NIST Risk Management Framework (RMF), after the system security plan is developed and approved (part of the Select step), the next major activity is to implement the security controls specified in that plan. This corresponds to the 'Implement' step (Step 3) of the RMF, where controls are put into place.
Developing a strategy for continuous monitoring (RMF Step 6, Monitor) is the final RMF step, occurring after authorization, to ensure ongoing security.
Concept tested: NIST RMF process flow - Implement step
Source: https://csrc.nist.gov/projects/risk-management-framework/rmf-steps
Topics
Community Discussion
No community discussion yet for this question.