CGRC · Question #115
In which of the following DIACAP phases is residual risk analyzed? Response:
The correct answer is B. Phase 4. The question asks to identify the specific phase within the Department of Defense Information Assurance Certification and Accreditation Process (DIACAP) where residual risk is analyzed.
Question
In which of the following DIACAP phases is residual risk analyzed? Response:
Options
- APhase 2
- BPhase 4
- CPhase 5
- DPhase 3
- EPhase 1
How the community answered
(35 responses)- A6% (2)
- B91% (32)
- E3% (1)
Why each option
The question asks to identify the specific phase within the Department of Defense Information Assurance Certification and Accreditation Process (DIACAP) where residual risk is analyzed.
Phase 2 ('Develop and Document DIACAP') focuses on developing the system's security plan and establishing security requirements.
DIACAP Phase 4 is 'Make Accreditation Determination and Authorize System.' During this phase, the certifying authority provides a certification report and recommendation to the Designated Approving Authority (DAA), who then reviews the entire package, including the Plan of Action and Milestones (POAM) and the remaining (residual) risks, to make the final authorization decision.
Phase 5 ('Maintain Authorization') involves continuous monitoring and managing changes to the system post-authorization.
Phase 3 ('Implement and Validate IA Controls') involves implementing and testing the security controls.
Phase 1 ('Initiate and Plan DIACAP') involves registering the system and defining the scope.
Concept tested: DIACAP phases and residual risk analysis
Topics
Community Discussion
No community discussion yet for this question.