nerdexam
(ISC)2

CAP · Question #137

Which of the following DoD directives defines DITSCAP as the standard C&A process for the Department of Defense?

The correct answer is B. DoD 5200.40. DoD Directive 5200.40, titled 'DoD Information Technology Security Certification and Accreditation Process (DITSCAP),' officially establishes DITSCAP as the standard process for certifying and accrediting DoD information systems. The other directives serve different purposes…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following DoD directives defines DITSCAP as the standard C&A process for the Department of Defense?

Options

  • ADoD 8000.1
  • BDoD 5200.40
  • CDoD 5200.22-M
  • DDoD 8910.1

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    90% (38)
  • C
    2% (1)

Explanation

DoD Directive 5200.40, titled 'DoD Information Technology Security Certification and Accreditation Process (DITSCAP),' officially establishes DITSCAP as the standard process for certifying and accrediting DoD information systems. The other directives serve different purposes: DoD 8000.1 covers information management, DoD 5200.22-M is the National Industrial Security Program Operating Manual (NISPOM) covering classified information for contractors, and DoD 8910.1 addresses information management control of reporting requirements.

Topics

#DITSCAP#C&A process#DoD Directives#Information Security Policy

Community Discussion

No community discussion yet for this question.

Full CAP Practice