100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

NIST RISK MANAGEMENT FRAMEWORK WITH COMPLETE SOLUTIONS

Rating
-
Sold
-
Pages
4
Grade
A+
Uploaded on
20-12-2024
Written in
2024/2025

NIST RISK MANAGEMENT FRAMEWORK WITH COMPLETE SOLUTIONS

Institution
NIST
Course
NIST








Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
NIST
Course
NIST

Document information

Uploaded on
December 20, 2024
Number of pages
4
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

NIST RISK MANAGEMENT FRAMEWORK
WITH COMPLETE SOLUTIONS
Difference between Nist cyber security framework and Risk management framework? -
NRMF is mandatory for government systems to abide by and but NCSF is not
compulsory for organizations to abide by. It is a recommendation but not a demand.

FIPS 199 - Standards for Security Categorization of Federal Information and Information
Systems

FISMA (Federal Information Security Management Act) - It is a federal law that was
passed in 2002 to protect government information, operations, and assets against any
security threats. When the Fisma law was passed all federal entities in the 50 states
where obliged to heed to the law.

How to categorize an information system? - 1. Software/System development life cycle
(SDLC) : is the various stages systems development right from building the coding until
the system decomposed or is of no use just like human life: from young to old


2. Information Type (category of information)
The individual types of information that goes into the application

3. Security Objectives (CIA):
-Insure Confidentiality (no one should see info unless authorized individual can access
info)
-integrity means that only authorized people should be able to modify or make changes
to the system
-availability: Application or system is always available for customers use

4. Potential impacts/impact levels to protect data or information for ex: Cashapp : HML
High, Moderate, Low determines how information system is categorized from HML

5. The High-water mark (security categorization/ overall categorization): It means the
Highest impact level out the impact levels of being HML

NIST 800-37 R2 - Is the mother document that NRMF procedure (7 steps) is based on
in order to protect federal organizations. It is the document that says every government
agency must comply with NRMF.

NIST 800-37 R2 .... Has 7 steps process - NIST 800-37 R2 is the guideline for Applying
the NIST Risk Management Framework to Federal Information Systems with 7 steps
which is:

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CLOUND Exam
View profile
Follow You need to be logged in order to follow users or courses
Sold
603
Member since
2 year
Number of followers
389
Documents
10901
Last sold
1 week ago
PROF MM

HELLO WELCOME TO THIS PAGE WHERE YOU WILL FIND ALL EXAMS ,STUDY GUIDE ,CASE, TESTBANKS AND ANY OTHER STUDY MATERIALS,

3.9

116 reviews

5
58
4
16
3
29
2
3
1
10

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions