CSC NIST Risk Management Framework 2 — Questions and Answers
Question 1: Which RMF step is responsible for selecting the initial set of security controls based on the system's impact level?
- Assess
- Select (Correct answer)
- Implement
- Authorize
Correct answer: Select
The Select step involves choosing appropriate security controls from NIST SP 800-53 based on the system categorization and impact level.
Question 2: What document formally records the security controls selected for an information system and their implementation status?
- Plan of Action and Milestones (POA&M)
- System Security Plan (SSP) (Correct answer)
- Security Assessment Report (SAR)
- Authorization to Operate (ATO)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) documents the selected controls, their implementation details, and the system's security posture.
Question 3: In the RMF Assess step, who typically conducts the security control assessment?
- The system owner
- An independent assessor or assessment team (Correct answer)
- The authorizing official
- The information system security officer
Correct answer: An independent assessor or assessment team
NIST requires that assessors be independent from the system development team to ensure objectivity and avoid conflicts of interest.
Question 4: What is the primary output of the RMF Assess step?
- Authorization to Operate (ATO)
- Plan of Action and Milestones (POA&M)
- Security Assessment Report (SAR) (Correct answer)
- System Security Plan (SSP)
Correct answer: Security Assessment Report (SAR)
The Security Assessment Report (SAR) documents the findings from the security control assessment, including deficiencies and recommendations.
Question 5: Which NIST publication provides the catalog of security and privacy controls used during the RMF Select step?
- NIST SP 800-37
- NIST SP 800-53 (Correct answer)
- NIST SP 800-30
- FIPS 199
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the comprehensive catalog of security and privacy controls that organizations select from during the RMF Select step.
Question 6: An organization identifies a control deficiency but cannot remediate it before the authorization deadline. What document captures this risk?
- System Security Plan (SSP)
- Security Assessment Report (SAR)
- Plan of Action and Milestones (POA&M) (Correct answer)
- Risk Executive Framework
Correct answer: Plan of Action and Milestones (POA&M)
The Plan of Action and Milestones (POA&M) formally documents known weaknesses, planned remediation actions, and target completion dates.
Question 7: In a federal context, who holds ultimate accountability for accepting the residual risk of operating an information system?
- Information System Security Officer (ISSO)
- System Owner
- Authorizing Official (AO) (Correct answer)
- Chief Information Officer (CIO)
Correct answer: Authorizing Official (AO)
The Authorizing Official (AO) is the senior official accountable for accepting residual risk and granting an Authorization to Operate.
Which RMF step is responsible for selecting the initial set of security controls based on the system's impact level?