CAP Risk Management Framework (RMF) 2 — Questions and Answers
Question 1: Which RMF step results in the formal decision to authorize a system to operate?
- Select
- Assess
- Authorize (Correct answer)
- Monitor
Correct answer: Authorize
The Authorize step is where the Authorizing Official reviews the risk and formally grants an Authorization to Operate (ATO).
Question 2: What document serves as the primary contract between the system owner and the Authorizing Official during RMF?
- Security Assessment Report
- System Security Plan (Correct answer)
- Plan of Action and Milestones
- Authorization Decision Document
Correct answer: System Security Plan
The System Security Plan (SSP) describes how security requirements are met and forms the basis for the authorization decision.
Question 3: In RMF terminology, what is a 'common control'?
- A control used only for classified systems
- A control inherited by multiple systems from a shared provider (Correct answer)
- A mandatory FIPS control
- A control applied at the network perimeter only
Correct answer: A control inherited by multiple systems from a shared provider
Common controls are security controls that can be inherited by multiple information systems from a centralized provider, reducing duplication.
Question 4: Which NIST publication provides guidance on security and privacy controls for federal information systems?
- NIST SP 800-30
- NIST SP 800-53 (Correct answer)
- NIST SP 800-37
- NIST SP 800-60
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the catalog of security and privacy controls used during the RMF Select step.
Question 5: What is the purpose of FIPS 199 in the RMF process?
- Defining encryption standards
- Establishing security categorization standards (Correct answer)
- Guiding incident response
- Outlining audit requirements
Correct answer: Establishing security categorization standards
FIPS 199 establishes standards for categorizing federal information and information systems based on potential impact (low, moderate, high).
Question 6: The RMF Implement step requires that security controls be implemented in accordance with which document?
- Security Assessment Report
- Authorization Decision
- System Security Plan (Correct answer)
- Continuous Monitoring Strategy
Correct answer: System Security Plan
Controls are implemented as described in the System Security Plan, which documents how each control is satisfied.
Which RMF step results in the formal decision to authorize a system to operate?