NIST Risk Management Framework Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 NIST Risk Management Framework flashcards as text
What is the relationship between the RMF and the NIST Cybersecurity Framework (CSF)?
Answer: The RMF is a risk management process while the CSF provides outcomes; RMF tasks can be mapped to CSF functions
The RMF is a process-oriented risk management lifecycle while the CSF is an outcome-based framework; NIST has published mappings showing how RMF steps align with CSF functions like Identify, Protect, Detect, Respond, and Recover.
Under the RMF, what is a 'security authorization boundary'?
Answer: The defined scope of an information system for which an AO accepts risk
The authorization boundary defines what resources, components, and data are included within the scope of the security authorization, determining what the ATO covers.
An authorizing official reviews an authorization package and determines the residual risk is acceptable. What is the next action?
Answer: Issue an Authorization to Operate (ATO)
Once the AO determines residual risk is acceptable, they issue an Authorization to Operate (ATO), formally permitting the system to process information.
What is a 'denial of authorization to operate' (DATO) and when is it issued?
Answer: A temporary suspension issued when a critical vulnerability is discovered that poses unacceptable risk
A DATO is issued when an AO determines that the risk of operating a system is unacceptable, often due to a critical unmitigated vulnerability, requiring immediate shutdown or remediation.
Which NIST publication provides guidance on conducting risk assessments as part of the RMF risk management process?
Answer: NIST SP 800-30
NIST SP 800-30 provides the guide for conducting risk assessments, including threat identification, vulnerability analysis, likelihood and impact determinations, and risk determination.
In the RMF, what is the significance of the 'authorization package'?
Answer: It is a collection of key documents (SSP, SAR, POA&M) submitted to the AO to support the authorization decision
The authorization package—comprising the SSP, SAR, and POA&M—gives the AO the comprehensive risk picture needed to make an informed authorization decision.
How does supply chain risk management (SCRM) integrate into the RMF under NIST SP 800-161?
Answer: SCRM controls are incorporated into the RMF by applying supply chain-specific controls during the Select and Implement steps
NIST SP 800-161 provides SCRM controls that are integrated into the RMF process, allowing organizations to address supply chain risks during control selection, implementation, and assessment.