NIST Risk Management Framework Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 NIST Risk Management Framework flashcards as text
Which RMF step is responsible for selecting the initial set of security controls based on the system's impact level?
Answer: Select
The Select step involves choosing appropriate security controls from NIST SP 800-53 based on the system categorization and impact level.
What document formally records the security controls selected for an information system and their implementation status?
Answer: System Security Plan (SSP)
The System Security Plan (SSP) documents the selected controls, their implementation details, and the system's security posture.
In the RMF Assess step, who typically conducts the security control assessment?
Answer: An independent assessor or assessment team
NIST requires that assessors be independent from the system development team to ensure objectivity and avoid conflicts of interest.
What is the primary output of the RMF Assess step?
Answer: Security Assessment Report (SAR)
The Security Assessment Report (SAR) documents the findings from the security control assessment, including deficiencies and recommendations.
Which NIST publication provides the catalog of security and privacy controls used during the RMF Select step?
Answer: NIST SP 800-53
NIST SP 800-53 provides the comprehensive catalog of security and privacy controls that organizations select from during the RMF Select step.
An organization identifies a control deficiency but cannot remediate it before the authorization deadline. What document captures this risk?
Answer: Plan of Action and Milestones (POA&M)
The Plan of Action and Milestones (POA&M) formally documents known weaknesses, planned remediation actions, and target completion dates.
In a federal context, who holds ultimate accountability for accepting the residual risk of operating an information system?
Answer: Authorizing Official (AO)
The Authorizing Official (AO) is the senior official accountable for accepting residual risk and granting an Authorization to Operate.