NIST Risk Management Framework Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 NIST Risk Management Framework flashcards as text
Which RMF step involves continuously tracking changes to the system and its environment that may affect security posture?
Answer: Monitor
The Monitor step requires ongoing surveillance of security controls, system changes, and threat environment to maintain situational awareness.
What triggers a significant change review that may require re-authorization of a system under the RMF?
Answer: Upgrading the operating system to a new major version
Major changes that significantly alter the system's attack surface or risk profile, such as OS upgrades, typically require a significant change review or re-authorization.
What is the concept of 'ongoing authorization' in the modern RMF?
Answer: Continuously monitoring and authorizing systems based on real-time risk data rather than fixed review cycles
Ongoing authorization shifts from point-in-time assessments to a continuous process where risk decisions are based on real-time monitoring data.
Which step in the RMF was added in Revision 2 of NIST SP 800-37 to better align security with the system development lifecycle?
Answer: Prepare
The Prepare step was added in SP 800-37 Rev. 2 to establish context and organizational priorities before executing the remaining RMF steps.
What is the purpose of the common control inheritance model in the RMF?
Answer: To enable systems to leverage security controls implemented by a provider organization, reducing duplication
Common control inheritance allows systems to leverage controls (e.g., physical security, HR policies) already implemented at an organizational level, reducing redundant implementation effort.
A cloud service provider's infrastructure is used by a federal agency. Under RMF, who is responsible for the security of the shared infrastructure controls?
Answer: The cloud service provider for infrastructure controls they manage
Under the shared responsibility model, the cloud service provider is responsible for infrastructure-layer controls they operate, while the agency is responsible for controls within its purview.
Which NIST publication provides guidance specifically on security and privacy controls assessment procedures used in the RMF Assess step?
Answer: NIST SP 800-53A
NIST SP 800-53A provides assessment procedures and methods for evaluating the effectiveness of controls documented in NIST SP 800-53.