โ† All CAP Flashcard Decks

Risk Management Framework Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Risk Management Framework flashcards as text
  1. What does FISMA stand for and what does it mandate?

    Answer: Federal Information Security Modernization Act; mandates federal agencies implement RMF-based security programs

    FISMA requires federal agencies to develop, document, and implement information security programs aligned with the RMF.

  2. What NIST publication provides guidance on organizational risk management as the overarching context for the RMF?

    Answer: NIST SP 800-39

    NIST SP 800-39 addresses managing information security risk at the organization, mission/business, and information system tiers.

  3. In the RMF three-tier hierarchy, which tier addresses mission and business process risk?

    Answer: Tier 2

    Tier 2 (Mission/Business Process) addresses risk at the mission and business process level between organizational leadership and system owners.

  4. Which term describes the maximum acceptable downtime for a system as defined in a Business Impact Analysis?

    Answer: Maximum Tolerable Downtime (MTD)

    MTD is the longest period an organization can survive without a critical system before business operations are permanently impaired.

  5. What is the primary goal of tailoring baseline security controls in the RMF?

    Answer: To adjust controls to the specific conditions, threat environment, and risk tolerance of the system

    Tailoring allows organizations to customize baseline controls to fit their specific operational environment, threat landscape, and risk posture.

  6. Which federal law requires Authorizing Officials to be senior agency officials with budget authority?

    Answer: FISMA

    FISMA requires that AOs be senior agency officials with authority over the resources and operations of the systems they authorize.