NIST Risk Management Framework Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 NIST Risk Management Framework flashcards as text
Under FIPS 199, which information type classification results in a HIGH impact level?
Answer: Loss would have a severe or catastrophic adverse effect on operations
FIPS 199 defines HIGH impact as a loss that would have a severe or catastrophic adverse effect on organizational operations, assets, or individuals.
What does the 'high-water mark' principle mean in the context of FIPS 199 system categorization?
Answer: The system's overall impact level equals the highest impact value among all information types it processes
The high-water mark principle means the overall system security category is set to the highest impact level assigned to any of its individual information types across confidentiality, integrity, and availability.
Which control baseline from NIST SP 800-53 is applied to systems categorized as MODERATE impact?
Answer: Moderate baseline
NIST SP 800-53 defines Low, Moderate, and High baselines corresponding to FIPS 199 impact levels; Moderate impact systems use the Moderate baseline.
What is 'tailoring' in the context of RMF control selection?
Answer: Modifying the baseline by adding, removing, or adjusting controls based on system-specific conditions
Tailoring involves adjusting the selected control baseline by adding compensating controls, removing non-applicable controls, or modifying parameters to fit the system's specific environment and risk.
An organization needs to document that a NIST SP 800-53 control does not apply to their system. What mechanism do they use?
Answer: Control scoping (non-applicability)
Control scoping, specifically declaring non-applicability, allows organizations to exclude controls that are not relevant to their operating environment when properly justified.
What role does the Information System Security Officer (ISSO) play in the RMF?
Answer: Manages day-to-day security operations and ensures controls are maintained for an assigned system
The ISSO serves as the primary point of contact for security matters related to a specific system, overseeing ongoing security operations and control maintenance.
Which artifact produced during the RMF Implement step provides evidence that controls were correctly configured?
Answer: Security Control Implementation Evidence
Security control implementation evidence—such as screenshots, configuration files, and logs—documents how each control was installed and configured as required.