Risk Management Framework (RMF) Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Risk Management Framework (RMF) flashcards as text
What NIST publication provides the primary guidance for the Risk Management Framework (RMF)?
Answer: NIST SP 800-37
NIST SP 800-37 provides the guide for applying the Risk Management Framework to federal information systems.
Which step of the RMF involves selecting the appropriate security controls for an information system?
Answer: Select
The Select step of the RMF involves choosing baseline security controls tailored to the system's categorization.
In the RMF, which step involves determining the security category of the information system?
Answer: Categorize
The Categorize step assigns a security impact level to the system using FIPS 199 and NIST SP 800-60.
What is the primary output of the RMF Assess step?
Answer: Security Assessment Report
The Security Assessment Report (SAR) documents the findings from evaluating the effectiveness of implemented security controls.
Which federal law mandates the use of the RMF for federal information systems?
Answer: FISMA
The Federal Information Security Modernization Act (FISMA) requires federal agencies to implement risk management frameworks.
The RMF Monitor step is primarily intended to provide what type of assurance?
Answer: Ongoing situational awareness
The Monitor step ensures continuous situational awareness of the security posture through ongoing assessments and reporting.