CAP Risk Management Framework (RMF) 1 — Questions and Answers
Question 1: What NIST publication provides the primary guidance for the Risk Management Framework (RMF)?
- NIST SP 800-37 (Correct answer)
- NIST SP 800-53
- NIST SP 800-171
- NIST SP 800-30
Correct answer: NIST SP 800-37
NIST SP 800-37 provides the guide for applying the Risk Management Framework to federal information systems.
Question 2: Which step of the RMF involves selecting the appropriate security controls for an information system?
- Categorize
- Select (Correct answer)
- Implement
- Assess
Correct answer: Select
The Select step of the RMF involves choosing baseline security controls tailored to the system's categorization.
Question 3: In the RMF, which step involves determining the security category of the information system?
- Authorize
- Monitor
- Categorize (Correct answer)
- Implement
Correct answer: Categorize
The Categorize step assigns a security impact level to the system using FIPS 199 and NIST SP 800-60.
Question 4: What is the primary output of the RMF Assess step?
- System Security Plan
- Authorization to Operate
- Security Assessment Report (Correct answer)
- Plan of Action and Milestones
Correct answer: Security Assessment Report
The Security Assessment Report (SAR) documents the findings from evaluating the effectiveness of implemented security controls.
Question 5: Which federal law mandates the use of the RMF for federal information systems?
- FISMA (Correct answer)
- HIPAA
- FERPA
- SOX
Correct answer: FISMA
The Federal Information Security Modernization Act (FISMA) requires federal agencies to implement risk management frameworks.
Question 6: The RMF Monitor step is primarily intended to provide what type of assurance?
- One-time certification
- Ongoing situational awareness (Correct answer)
- Initial risk acceptance
- Control selection validation
Correct answer: Ongoing situational awareness
The Monitor step ensures continuous situational awareness of the security posture through ongoing assessments and reporting.
What NIST publication provides the primary guidance for the Risk Management Framework (RMF)?