RMF Task/Description v Phase and Role Flashcards
1
Q
1-1: Security Categorization
A
- Initiation
- ISO and IO/Steward
2
Q
1-2: Information System Description
A
- Initiation
- ISO
3
Q
1-3: Information System Registration
A
- Initiation
- ISO
4
Q
2-1: Common Control Identification
A
- Initiation
- CIO, CISO, CCP, ISA
5
Q
2-2: Security Control Selection
A
- Initiation
- ISO and ISA
6
Q
2-3: Continuous Monitoring Strategy
A
- Initiation
- CCP and ISO
7
Q
2-4: Security Plan Approval
A
- Development
- AO and AODR
8
Q
3-1: Security Control Implementation
A
- Development and Implementation
- CCP and ISO
9
Q
3-2: Security Control Documentation
A
- Development and Implementation
- CCP and ISO
10
Q
4-1: Assessment Preparation
A
- Development and Implementation
- SCA
11
Q
4-2: Security Control Assessment
A
- Development and Implementation
- SCA
12
Q
4-3: Security Assessment Report (SAR)
A
- Development and Implementation
- SCA
13
Q
4-4: Remediation Actions
A
- Development and Implementation
- SCA, CCP and ISO
14
Q
5-1: Plan of Actions and Milestones (POAMs)
A
- Implementation
- CCP and ISO
15
Q
5-2: Security Authorization Package
A
- Implementation
- CCP and ISO