nerdexam
(ISC)2

CAP · Question #177

Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or…

The correct answer is A. Accreditation is the official management decision given by a senior agency official to authorize B. Certification is a comprehensive assessment of the management, operational, and technical. In the C&A framework (as defined by NIST and FISMA): Certification (Option B) is the comprehensive technical assessment of management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly…

System Compliance

Question

Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation? Each correct answer represents a complete solution. Choose two.

Options

  • AAccreditation is the official management decision given by a senior agency official to authorize
  • BCertification is a comprehensive assessment of the management, operational, and technical
  • CAccreditation is a comprehensive assessment of the management, operational, and technical
  • DCertification is the official management decision given by a senior agency official to authorize

How the community answered

(58 responses)
  • A
    91% (53)
  • C
    5% (3)
  • D
    3% (2)

Explanation

In the C&A framework (as defined by NIST and FISMA): Certification (Option B) is the comprehensive technical assessment of management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly and producing the desired outcome. Accreditation (Option A) is the official management decision made by a senior agency official (the Authorizing Official) to authorize operation of an information system, accepting the residual risk. Options C and D reverse these definitions - Accreditation is not the assessment process, and Certification is not the management authorization decision.

Topics

#Certification#Accreditation#C&A#Risk Management Framework

Community Discussion

No community discussion yet for this question.

Full CAP Practice