<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NIST 37 question in Exams</title>
    <link>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75182#M3609</link>
    <description>&lt;P&gt;You are correct. This question is an example of insufficient quality control on the part of the question provider.&lt;/P&gt;</description>
    <pubDate>Sun, 17 Nov 2024 17:09:05 GMT</pubDate>
    <dc:creator>dips0502</dc:creator>
    <dc:date>2024-11-17T17:09:05Z</dc:date>
    <item>
      <title>NIST 37 question</title>
      <link>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75166#M3603</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NIST800-37.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9196iF4773DE712BC2ABF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="NIST800-37.png" alt="NIST800-37.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In my understanding NIST-37: Risk Management (Federal Government): Guidelines on managing cybersecurity risks (e.g., NIST SP 800-37 for the Risk Management Framework).&amp;nbsp; Where &amp;nbsp;NIST SP 800-53: covers "Security and Privacy Controls for Information Systems and Organizations" provides a comprehensive set of security and privacy controls that can be tailored to the specific needs of an organization.&amp;nbsp; Can you let me know why 800-53 is the better answer?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 20:57:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75166#M3603</guid>
      <dc:creator>Surferway</dc:creator>
      <dc:date>2024-11-15T20:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: NIST 37 question</title>
      <link>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75173#M3605</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It is very difficult which angle one answer is better than the others.when both are so close.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My thinking as follows:&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;SP 800-53&lt;/STRONG&gt;: Lists the security and privacy controls to be &lt;STRONG&gt;used within the RMF&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;SP 800-37&lt;/STRONG&gt;&lt;SPAN&gt;: Details the RMF process&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with you alternative &lt;STRONG&gt;C 800-37&lt;/STRONG&gt; is correct&amp;nbsp; because it specifically details the Risk Management Framework (RMF). While B. 800-53 is&amp;nbsp; very closely related and provides the security and privacy controls used within the RMF, it does not detail the RMF process itself. Therefore, i consider , 800-37 is the correct choice for the publication that outlines the RMF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes, the expert who formulize the question should ask why B is better than C.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mahfujur&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2024 15:25:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75173#M3605</guid>
      <dc:creator>Mahfujur</dc:creator>
      <dc:date>2024-11-16T15:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: NIST 37 question</title>
      <link>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75179#M3607</link>
      <description>&lt;P&gt;Thanks for the confirmation, that was my thinking as well.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2024 12:41:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75179#M3607</guid>
      <dc:creator>Surferway</dc:creator>
      <dc:date>2024-11-17T12:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: NIST 37 question</title>
      <link>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75180#M3608</link>
      <description>You are welcome.&lt;BR /&gt;Br&lt;BR /&gt;Mahfuj</description>
      <pubDate>Sun, 17 Nov 2024 14:25:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75180#M3608</guid>
      <dc:creator>Mahfujur</dc:creator>
      <dc:date>2024-11-17T14:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: NIST 37 question</title>
      <link>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75182#M3609</link>
      <description>&lt;P&gt;You are correct. This question is an example of insufficient quality control on the part of the question provider.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2024 17:09:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75182#M3609</guid>
      <dc:creator>dips0502</dc:creator>
      <dc:date>2024-11-17T17:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: NIST 37 question</title>
      <link>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75281#M3625</link>
      <description>&lt;P&gt;Here is detail about your question:&amp;nbsp;NIST management framework standard against which audits, and control assessments will be performed. Which NIST special publication (SP) details the RMF?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Correct Answer: &amp;nbsp;800-53&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://csrc.nist.rip/Projects/risk-management/sp800-53-controls/release-search#!/families?version=5.1" target="_blank"&gt;https://csrc.nist.rip/Projects/risk-management/sp800-53-controls/release-search#!/families?version=5.1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Nov 2024 02:19:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/NIST-37-question/m-p/75281#M3625</guid>
      <dc:creator>MALVIKA</dc:creator>
      <dc:date>2024-11-24T02:19:47Z</dc:date>
    </item>
  </channel>
</rss>

