CGRC Risk Management Framework 3 — Questions and Answers
Question 1: An organization operates a cloud-hosted system and wants to leverage an existing FedRAMP authorization. Which RMF concept supports reusing another system's security authorization package?
- Reciprocity (Correct answer)
- Tailoring
- Overlays
- Continuous Monitoring
Correct answer: Reciprocity
Reciprocity allows organizations to accept an existing authorization package rather than duplicating assessment efforts, reducing redundancy.
Question 2: What is the purpose of a Plan of Action and Milestones (POA&M) in the RMF?
- To document the system's authorization boundary
- To track remediation of identified security weaknesses (Correct answer)
- To list approved security controls for the system
- To record the results of security control assessments
Correct answer: To track remediation of identified security weaknesses
The POA&M is a corrective action plan that tracks identified vulnerabilities and weaknesses, their remediation status, and target completion dates.
Question 3: When applying the RMF, what does 'tailoring' security controls mean?
- Replacing all baseline controls with custom-built solutions
- Adding, removing, or modifying controls from a baseline to fit the system's environment (Correct answer)
- Assigning controls to specific staff members
- Documenting controls in the System Security Plan
Correct answer: Adding, removing, or modifying controls from a baseline to fit the system's environment
Tailoring allows organizations to adjust the control baseline by adding compensating controls, scoping controls, or applying parameter values appropriate to their risk environment.
Question 4: In the NIST RMF, which document serves as the primary artifact describing the security posture of an information system?
- Security Assessment Report (SAR)
- Plan of Action and Milestones (POA&M)
- System Security Plan (SSP) (Correct answer)
- Authorization Decision Document
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) describes the system environment, security requirements, and the controls in place or planned to protect the system.
Question 5: Which NIST publication guides how to categorize federal information and information systems for security purposes?
- NIST SP 800-53
- NIST SP 800-37
- FIPS 199 and NIST SP 800-60 (Correct answer)
- NIST SP 800-30
Correct answer: FIPS 199 and NIST SP 800-60
FIPS 199 defines the standards for categorization, and NIST SP 800-60 maps information types to security impact levels for use during the Categorize step.
Question 6: A new interconnection is established between a federal system and a contractor's network. Which document should be created to formalize the security requirements for this connection?
- System Security Plan addendum
- Memorandum of Understanding (MOU)
- Interconnection Security Agreement (ISA) (Correct answer)
- Plan of Action and Milestones
Correct answer: Interconnection Security Agreement (ISA)
An Interconnection Security Agreement (ISA) documents the security controls and responsibilities agreed upon by both parties for a system interconnection.
Question 7: Which RMF step uses automated tools such as vulnerability scanners and Security Information and Event Management (SIEM) systems to maintain ongoing situational awareness?
- Assess
- Implement
- Authorize
- Monitor (Correct answer)
Correct answer: Monitor
The Monitor step leverages automated tools to continuously evaluate security control effectiveness and detect changes that may affect the authorization.
An organization operates a cloud-hosted system and wants to leverage an existing FedRAMP authorization.
Which RMF concept supports reusing another system's security authorization package?