Study. uk . com
  1. Home
  2. All questions
  3. Question 592

CISM study material · question 592 of 1000

What determination does the RMF Authorize step make, and what can it cover?

  1. That the security plan is complete — covering the organisation
  2. That controls have been correctly implemented — covering a system only
  3. That risk to operations, assets, individuals and others is acceptable — covering a system or a set of common controls
  4. That monitoring is in place — covering the control baseline
Show the answer

Answer: C. That risk to operations, assets, individuals and others is acceptable — covering a system or a set of common controls

SP 800-37's Authorize step turns on whether risk to operations, assets, individuals, other organisations and the Nation is acceptable, and applies to a system or to a set of common controls.

Source: NIST SP 800-37 Rev. 2 (NIST) — Sec. 2.2 RMF Steps and Structure

Challenge yourself on this topic → Study as cards