nerdexam
(ISC)2

CAP · Question #194

In which of the following DITSCAP phases is the SSAA developed?

The correct answer is C. Phase 1. DITSCAP (DoD Information Technology Security Certification and Accreditation Process) has four phases: Phase 1 (Definition), Phase 2 (Verification), Phase 3 (Validation), and Phase 4 (Post-Accreditation). The System Security Authorization Agreement (SSAA) is the cornerstone…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

In which of the following DITSCAP phases is the SSAA developed?

Options

  • APhase 4
  • BPhase 2
  • CPhase 1
  • DPhase 3

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    88% (38)
  • D
    2% (1)

Explanation

DITSCAP (DoD Information Technology Security Certification and Accreditation Process) has four phases: Phase 1 (Definition), Phase 2 (Verification), Phase 3 (Validation), and Phase 4 (Post-Accreditation). The System Security Authorization Agreement (SSAA) is the cornerstone document of DITSCAP and is created and agreed upon during Phase 1 (Definition). It defines the system's security requirements, boundaries, and the roles/responsibilities of all parties. Subsequent phases use the SSAA as a reference to verify, validate, and maintain compliance.

Topics

#DITSCAP#SSAA#Certification and Accreditation (C&A)#Security Plan Development

Community Discussion

No community discussion yet for this question.

Full CAP Practice