nerdexam
(ISC)2

CAP · Question #64

Which of the following phases of the DITSCAP C&A process is used to define the C&A level of effort, to identify the main C&A roles and responsibilities, and to create an agreement on the method for…

The correct answer is D. Phase 1. DITSCAP (DoD Information Technology Security Certification and Accreditation Process) consists of four phases. Phase 1 - Definition - is the correct answer. In this phase, the mission, environment, system architecture, and security requirements are established. The key outputs…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following phases of the DITSCAP C&A process is used to define the C&A level of effort, to identify the main C&A roles and responsibilities, and to create an agreement on the method for implementing the security requirements?

Options

  • APhase 3
  • BPhase 2
  • CPhase 4
  • DPhase 1

How the community answered

(38 responses)
  • A
    5% (2)
  • C
    3% (1)
  • D
    92% (35)

Explanation

DITSCAP (DoD Information Technology Security Certification and Accreditation Process) consists of four phases. Phase 1 - Definition - is the correct answer. In this phase, the mission, environment, system architecture, and security requirements are established. The key outputs include defining the C&A level of effort, identifying the primary roles and responsibilities, and reaching a formal agreement (captured in the System Security Authorization Agreement, or SSAA) on how security requirements will be implemented. This foundational work must occur before any security testing or evaluation begins in later phases.

Topics

#DITSCAP#C&A process#Security requirements#Phase 1

Community Discussion

No community discussion yet for this question.

Full CAP Practice