Risk Management Framework (RMF) Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Risk Management Framework (RMF) flashcards as text
Which RMF step was added in NIST SP 800-37 Revision 2 to emphasize security early in the system lifecycle?
Answer: Prepare
The Prepare step was introduced in RMF Rev. 2 to establish organization- and system-level context before beginning the RMF process.
What is the meaning of 'residual risk' in the context of the RMF Authorize step?
Answer: Risk remaining after controls are applied
Residual risk is the remaining level of risk after security controls have been applied to the information system.
Under RMF, who has final authority to accept the risk associated with operating an information system?
Answer: Authorizing Official
The Authorizing Official (AO) is the senior official who accepts responsibility for the residual risk and grants the ATO.
A Plan of Action and Milestones (POA&M) is used to track what?
Answer: Weaknesses and remediation plans for security controls
The POA&M documents identified security weaknesses, responsible parties, and scheduled remediation milestones.
Which component of an authorization package summarizes the overall risk posture of a system?
Answer: Executive Summary / Risk Summary
The executive or risk summary provides the Authorizing Official a concise overview of residual risk to support the authorization decision.
What is the typical duration of an Authorization to Operate (ATO) before it requires renewal?
Answer: 3 years
ATOs are typically granted for a period of three years, after which the system must undergo re-authorization.