โ† All CAP Flashcard Decks

Risk Management Framework (RMF) Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Risk Management Framework (RMF) flashcards as text
  1. Which RMF step was added in NIST SP 800-37 Revision 2 to emphasize security early in the system lifecycle?

    Answer: Prepare

    The Prepare step was introduced in RMF Rev. 2 to establish organization- and system-level context before beginning the RMF process.

  2. What is the meaning of 'residual risk' in the context of the RMF Authorize step?

    Answer: Risk remaining after controls are applied

    Residual risk is the remaining level of risk after security controls have been applied to the information system.

  3. Under RMF, who has final authority to accept the risk associated with operating an information system?

    Answer: Authorizing Official

    The Authorizing Official (AO) is the senior official who accepts responsibility for the residual risk and grants the ATO.

  4. A Plan of Action and Milestones (POA&M) is used to track what?

    Answer: Weaknesses and remediation plans for security controls

    The POA&M documents identified security weaknesses, responsible parties, and scheduled remediation milestones.

  5. Which component of an authorization package summarizes the overall risk posture of a system?

    Answer: Executive Summary / Risk Summary

    The executive or risk summary provides the Authorizing Official a concise overview of residual risk to support the authorization decision.

  6. What is the typical duration of an Authorization to Operate (ATO) before it requires renewal?

    Answer: 3 years

    ATOs are typically granted for a period of three years, after which the system must undergo re-authorization.