CGRC Risk Management Framework 2 — Questions and Answers
Question 1: In the NIST RMF, which step involves defining the system boundary and identifying stakeholders responsible for the information system?
- Assess
- Prepare (Correct answer)
- Categorize
- Select
Correct answer: Prepare
The Prepare step establishes the context and prerequisites for all subsequent RMF tasks, including defining system boundaries and identifying roles.
Question 2: Which NIST publication provides the catalog of security and privacy controls used in the RMF Select step?
- NIST SP 800-37
- NIST SP 800-53 (Correct answer)
- NIST SP 800-30
- NIST SP 800-60
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the catalog of security and privacy controls that organizations select from during the RMF Select step.
Question 3: A system owner wants to accept the residual risk after implementing security controls. Which RMF step does this decision occur in?
- Implement
- Assess
- Authorize (Correct answer)
- Monitor
Correct answer: Authorize
The Authorize step is where the Authorizing Official (AO) formally accepts residual risk and grants or denies an Authorization to Operate (ATO).
Question 4: What document produced during the RMF Assess step summarizes the results of security control testing?
- System Security Plan (SSP)
- Security Assessment Report (SAR) (Correct answer)
- Plan of Action and Milestones (POA&M)
- Authorization Package
Correct answer: Security Assessment Report (SAR)
The Security Assessment Report (SAR) documents the assessment methods, findings, and recommendations from the Assess step.
Question 5: Under FISMA, how often must federal systems with an ATO undergo reauthorization if no significant change occurs?
- Every year
- Every two years
- Every three years
- Continuous monitoring replaces fixed reauthorization cycles (Correct answer)
Correct answer: Continuous monitoring replaces fixed reauthorization cycles
NIST SP 800-37 Rev. 2 shifted from fixed 3-year reauthorization cycles to ongoing authorization supported by continuous monitoring.
Question 6: Which role in the RMF is responsible for ensuring security controls are correctly implemented in the information system?
- Authorizing Official (AO)
- System Owner (Correct answer)
- Security Control Assessor (SCA)
- Chief Information Officer (CIO)
Correct answer: System Owner
The System Owner is responsible for implementing security controls and ensuring the system operates as described in the System Security Plan.
Question 7: Which RMF task involves mapping an information system to impact levels (Low, Moderate, High) based on the potential harm a breach could cause?
- Prepare
- Select
- Categorize (Correct answer)
- Implement
Correct answer: Categorize
The Categorize step uses FIPS 199 and NIST SP 800-60 to assign security impact levels based on confidentiality, integrity, and availability consequences.
In the NIST RMF, which step involves defining the system boundary and identifying stakeholders responsible for the information system?