Which outcome states that control baselines necessary to protect the system commensurate with risk are selected?

Study for the RMF Steps, Tasks, and Outcomes Test. Get ready for your exam with flashcards, multiple choice questions, and in-depth explanations. Master each step and outcome with ease!

Multiple Choice

Which outcome states that control baselines necessary to protect the system commensurate with risk are selected?

Explanation:
Selecting control baselines that protect the system in line with its risk level is about choosing a set of security controls that matches the system’s risk. In this approach, baselines provide a starting point and are tailored to the specific risk profile so the protections are commensurate with the potential impact. That description directly captures the action of choosing the appropriate baseline controls based on risk. The other descriptions refer to different parts of the process—where the system fits in the enterprise architecture, defining and prioritizing security and privacy requirements, or registering the system for management and oversight—which are separate steps and do not describe the actual baseline selection.

Selecting control baselines that protect the system in line with its risk level is about choosing a set of security controls that matches the system’s risk. In this approach, baselines provide a starting point and are tailored to the specific risk profile so the protections are commensurate with the potential impact. That description directly captures the action of choosing the appropriate baseline controls based on risk.

The other descriptions refer to different parts of the process—where the system fits in the enterprise architecture, defining and prioritizing security and privacy requirements, or registering the system for management and oversight—which are separate steps and do not describe the actual baseline selection.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy