nerdexam
(ISC)2

CAP · Question #318

Which of the following describes residual risk as the risk remaining after risk mitigation has occurred?

The correct answer is A. DIACAP. DIACAP (DoD Information Assurance Certification and Accreditation Process) is the DoD framework that formally defines residual risk as the risk remaining after security controls and mitigations have been applied.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following describes residual risk as the risk remaining after risk mitigation has occurred?

Options

  • ADIACAP
  • BISSO
  • CSSAA
  • DDAA

How the community answered

(15 responses)
  • A
    87% (13)
  • B
    7% (1)
  • C
    7% (1)

Why each option

DIACAP (DoD Information Assurance Certification and Accreditation Process) is the DoD framework that formally defines residual risk as the risk remaining after security controls and mitigations have been applied.

ADIACAPCorrect

DIACAP is the Department of Defense process for certifying and accrediting information systems, and it formally defines residual risk as the level of risk that persists after security controls have been implemented and risk mitigation measures have been applied. The Designated Accrediting Authority (DAA) uses this residual risk determination to decide whether to grant accreditation and whether the remaining risk is acceptable for mission operations. DIACAP provides the structured, end-to-end process for evaluating, documenting, and accepting residual risk in DoD information systems.

BISSO

ISSO (Information System Security Officer) is a personnel role responsible for day-to-day security oversight of a system, not a framework or document that defines the concept of residual risk.

CSSAA

SSAA (System Security Authorization Agreement) is a DIACAP document that captures system security requirements and controls but does not itself define residual risk as a conceptual term.

DDAA

DAA (Designated Accrediting Authority) is a role that accepts risk on behalf of the organization under DIACAP, not a framework or standard that defines what residual risk means.

Concept tested: DIACAP residual risk definition after mitigation

Source: https://csrc.nist.gov/glossary/term/diacap

Topics

#Residual Risk#Risk Mitigation#DIACAP#Certification and Accreditation

Community Discussion

No community discussion yet for this question.

Full CAP Practice