โ† All CAP Flashcard Decks

Risk Management Framework (RMF) Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Risk Management Framework (RMF) flashcards as text
  1. What NIST publication provides the primary guidance for the Risk Management Framework (RMF)?

    Answer: NIST SP 800-37

    NIST SP 800-37 provides the guide for applying the Risk Management Framework to federal information systems.

  2. Which step of the RMF involves selecting the appropriate security controls for an information system?

    Answer: Select

    The Select step of the RMF involves choosing baseline security controls tailored to the system's categorization.

  3. In the RMF, which step involves determining the security category of the information system?

    Answer: Categorize

    The Categorize step assigns a security impact level to the system using FIPS 199 and NIST SP 800-60.

  4. What is the primary output of the RMF Assess step?

    Answer: Security Assessment Report

    The Security Assessment Report (SAR) documents the findings from evaluating the effectiveness of implemented security controls.

  5. Which federal law mandates the use of the RMF for federal information systems?

    Answer: FISMA

    The Federal Information Security Modernization Act (FISMA) requires federal agencies to implement risk management frameworks.

  6. The RMF Monitor step is primarily intended to provide what type of assurance?

    Answer: Ongoing situational awareness

    The Monitor step ensures continuous situational awareness of the security posture through ongoing assessments and reporting.