CAP · Question #64
Which of the following phases of the DITSCAP C&A process is used to define the C&A level of effort, to identify the main C&A roles and responsibilities, and to create an agreement on the method for…
The correct answer is D. Phase 1. DITSCAP (DoD Information Technology Security Certification and Accreditation Process) consists of four phases. Phase 1 - Definition - is the correct answer. In this phase, the mission, environment, system architecture, and security requirements are established. The key outputs…
Question
Which of the following phases of the DITSCAP C&A process is used to define the C&A level of effort, to identify the main C&A roles and responsibilities, and to create an agreement on the method for implementing the security requirements?
Options
- APhase 3
- BPhase 2
- CPhase 4
- DPhase 1
How the community answered
(38 responses)- A5% (2)
- C3% (1)
- D92% (35)
Explanation
DITSCAP (DoD Information Technology Security Certification and Accreditation Process) consists of four phases. Phase 1 - Definition - is the correct answer. In this phase, the mission, environment, system architecture, and security requirements are established. The key outputs include defining the C&A level of effort, identifying the primary roles and responsibilities, and reaching a formal agreement (captured in the System Security Authorization Agreement, or SSAA) on how security requirements will be implemented. This foundational work must occur before any security testing or evaluation begins in later phases.
Topics
Community Discussion
No community discussion yet for this question.