FedRAMP Risk Management Framework & Assessment 2 — Questions and Answers
Question 1: Which NIST publication specifically defines the Risk Management Framework (RMF) steps used in FedRAMP?
- NIST SP 800-37 (Correct answer)
- NIST SP 800-53
- NIST SP 800-30
- NIST SP 800-171
Correct answer: NIST SP 800-37
NIST SP 800-37, 'Guide for Applying the Risk Management Framework to Federal Information Systems,' defines the six RMF steps that FedRAMP is built upon.
Question 2: In FedRAMP, which step of the RMF involves selecting and tailoring security controls based on the system's categorization?
- Categorize
- Select (Correct answer)
- Implement
- Assess
Correct answer: Select
The Select step involves choosing appropriate security controls from NIST SP 800-53 and applying FedRAMP baselines and overlays based on the system's impact level.
Question 3: A CSP's system stores federal tax records for millions of citizens. Under FIPS 199, which impact level is most appropriate?
- Low
- Moderate
- High (Correct answer)
- Critical
Correct answer: High
Systems storing sensitive federal data like tax records affecting millions of citizens typically warrant a High impact categorization due to severe consequences if compromised.
Question 4: What does the term 'residual risk' mean in the context of FedRAMP risk assessments?
- Risk identified but not yet assigned to an owner
- Risk that remains after security controls have been applied (Correct answer)
- Risk transferred to a third-party subcontractor
- Risk documented in the POA&M but not yet remediated
Correct answer: Risk that remains after security controls have been applied
Residual risk is the remaining risk exposure after all planned or implemented security controls have been applied to mitigate or reduce the initial risk.
Question 5: Which document formally records the security control implementation details for a FedRAMP system?
- System Security Plan (SSP) (Correct answer)
- Plan of Action & Milestones (POA&M)
- Security Assessment Report (SAR)
- Authorization to Operate (ATO)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) is the primary document describing how each security control is implemented, who is responsible, and the system's security posture.
Question 6: During RMF's Assess step, what is the primary role of the Third Party Assessment Organization (3PAO)?
- Authorize the system for federal use
- Independently test and evaluate security control effectiveness (Correct answer)
- Develop the remediation plan for identified gaps
- Issue the Authority to Operate letter
Correct answer: Independently test and evaluate security control effectiveness
The 3PAO conducts an independent assessment to test and validate that the CSP's security controls are implemented correctly and operating as intended.
Question 7: Which risk response strategy involves accepting the risk without taking any additional mitigation actions?
- Risk avoidance
- Risk transfer
- Risk acceptance (Correct answer)
- Risk mitigation
Correct answer: Risk acceptance
Risk acceptance means the authorizing official acknowledges a known risk and decides no further action is warranted, often because the cost of mitigation outweighs the potential impact.
Which NIST publication specifically defines the Risk Management Framework (RMF) steps used in FedRAMP?