CGRC Risk Management Framework 5 — Questions and Answers
Question 1: An organization identifies a high-severity vulnerability in a production system that has an active ATO. What RMF action is most appropriate?
- Wait until the next annual review to address it
- Update the SSP and notify the AO; remediate based on POA&M timelines (Correct answer)
- Immediately revoke the ATO and shut down the system
- Transfer the risk to the system's vendor
Correct answer: Update the SSP and notify the AO; remediate based on POA&M timelines
Newly discovered vulnerabilities should be documented in the POA&M, the SSP updated as needed, and the AO notified so they can determine if the authorization remains valid.
Question 2: Which NIST publication provides guidance on conducting risk assessments as part of the RMF Prepare step?
- NIST SP 800-53
- NIST SP 800-37
- NIST SP 800-30 (Correct answer)
- NIST SP 800-60
Correct answer: NIST SP 800-30
NIST SP 800-30 provides the Guide for Conducting Risk Assessments, which supports threat and vulnerability identification during the Prepare and Assess steps.
Question 3: A system undergoes a significant change — a new authentication module is added. What RMF action is required?
- No action is needed if the ATO is still valid
- Conduct an impact analysis and potentially reassess affected controls (Correct answer)
- Issue a new ATO from scratch for the entire system
- Remove the system from the network during testing
Correct answer: Conduct an impact analysis and potentially reassess affected controls
Significant changes trigger an impact analysis per NIST SP 800-37 to determine whether affected controls must be reassessed and whether reauthorization is needed.
Question 4: Which term describes the aggregated risk from multiple Low-impact systems that, combined, could have a significant security impact on an organization?
- Residual risk
- Inherited risk
- Aggregate risk (Correct answer)
- Transferred risk
Correct answer: Aggregate risk
Aggregate risk refers to the combined risk from interconnected or related systems that may each individually pose Low risk but collectively create greater organizational exposure.
Question 5: In a multi-tier RMF implementation, which organizational tier is responsible for defining mission and business processes that drive information security requirements?
- Tier 1 – Organization
- Tier 2 – Mission/Business Process (Correct answer)
- Tier 3 – Information System
- Tier 4 – Operational
Correct answer: Tier 2 – Mission/Business Process
NIST SP 800-37 defines Tier 2 as the Mission/Business Process level, where enterprise architects and process owners translate organizational goals into security requirements.
Question 6: Which authorization approach allows an Authorizing Official to grant approval for a type of system rather than evaluating each instance individually?
- Site-based authorization
- Type authorization (Correct answer)
- Ongoing authorization
- Joint authorization
Correct answer: Type authorization
Type authorization grants an ATO to a category of identically configured systems, allowing reuse of a single authorization package across multiple instances.
Question 7: What distinguishes 'ongoing authorization' from the traditional fixed-term ATO model in NIST SP 800-37 Rev. 2?
- Ongoing authorization requires no security assessments
- Ongoing authorization uses continuous monitoring data to maintain situational awareness and make real-time risk decisions (Correct answer)
- Ongoing authorization is only available to cloud service providers
- Ongoing authorization eliminates the need for a POA&M
Correct answer: Ongoing authorization uses continuous monitoring data to maintain situational awareness and make real-time risk decisions
Ongoing authorization leverages continuous monitoring to provide the AO with near real-time risk information, enabling dynamic authorization decisions rather than periodic snapshots.
An organization identifies a high-severity vulnerability in a production system that has an active ATO.
What RMF action is most appropriate?