nerdexam
(ISC)2

CAP · Question #184

Certification and Accreditation (C&A or CnA) is a process for implementing information security. Which of the following is the correct order of C&A phases in a DITSCAP assessment?

The correct answer is C. Definition, Verification, Validation, and Post Accreditation. The correct order of DITSCAP (Defense Information Technology Security Certification and Accreditation Process) phases is Definition → Verification → Validation → Post Accreditation (C). In Phase 1 (Definition), the mission and security requirements are defined in a System…

Assessment/Audit of Security and Privacy Controls

Question

Certification and Accreditation (C&A or CnA) is a process for implementing information security. Which of the following is the correct order of C&A phases in a DITSCAP assessment?

Options

  • ADefinition, Validation, Verification, and Post Accreditation
  • BVerification, Definition, Validation, and Post Accreditation
  • CDefinition, Verification, Validation, and Post Accreditation
  • DVerification, Validation, Definition, and Post Accreditation

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    88% (28)
  • D
    3% (1)

Explanation

The correct order of DITSCAP (Defense Information Technology Security Certification and Accreditation Process) phases is Definition → Verification → Validation → Post Accreditation (C). In Phase 1 (Definition), the mission and security requirements are defined in a System Security Authorization Agreement (SSAA). Phase 2 (Verification) ensures the system complies with the SSAA. Phase 3 (Validation) confirms the system operates securely in its target environment. Phase 4 (Post Accreditation) covers ongoing operations and maintenance. The other answer choices present this sequence out of order.

Topics

#C&A phases#DITSCAP#Accreditation Process#Information Security Process

Community Discussion

No community discussion yet for this question.

Full CAP Practice