nerdexam
(ISC)2

CGRC · Question #96

The initial security plan for a new application has been approved. What is the next activity in the Risk Management Framework? Response:

The correct answer is C. Implement the security controls specified in the system security plan. After the initial security plan for a new application is approved within the Risk Management Framework (RMF), the next activity is to implement the security controls specified in that plan.

Implementation of Security and Privacy Controls

Question

The initial security plan for a new application has been approved. What is the next activity in the Risk Management Framework? Response:

Options

  • AAsses a selected subset of the security controls inherited by the information system.
  • BAssemble the security authorization package.
  • CImplement the security controls specified in the system security plan.
  • DDevelop a strategy for the continuous monitoring of security control effectiveness.

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    92% (44)
  • D
    2% (1)

Why each option

After the initial security plan for a new application is approved within the Risk Management Framework (RMF), the next activity is to implement the security controls specified in that plan.

AAsses a selected subset of the security controls inherited by the information system.

Assessing controls (RMF Step 4) occurs after implementation, to determine if they are correctly implemented, operating as intended, and producing the desired outcome.

BAssemble the security authorization package.

Assembling the security authorization package (RMF Step 5, Authorize) occurs after controls are implemented and assessed, as the package contains the evidence for the authorization decision.

CImplement the security controls specified in the system security plan.Correct

According to the NIST Risk Management Framework (RMF), after the system security plan is developed and approved (part of the Select step), the next major activity is to implement the security controls specified in that plan. This corresponds to the 'Implement' step (Step 3) of the RMF, where controls are put into place.

DDevelop a strategy for the continuous monitoring of security control effectiveness.

Developing a strategy for continuous monitoring (RMF Step 6, Monitor) is the final RMF step, occurring after authorization, to ensure ongoing security.

Concept tested: NIST RMF process flow - Implement step

Source: https://csrc.nist.gov/projects/risk-management-framework/rmf-steps

Topics

#Risk Management Framework#NIST RMF Steps#Security Control Implementation#System Security Plan

Community Discussion

No community discussion yet for this question.

Full CGRC Practice