nerdexam
(ISC)2

CGRC · Question #115

In which of the following DIACAP phases is residual risk analyzed? Response:

The correct answer is B. Phase 4. The question asks to identify the specific phase within the Department of Defense Information Assurance Certification and Accreditation Process (DIACAP) where residual risk is analyzed.

Compliance Maintenance

Question

In which of the following DIACAP phases is residual risk analyzed? Response:

Options

  • APhase 2
  • BPhase 4
  • CPhase 5
  • DPhase 3
  • EPhase 1

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    91% (32)
  • E
    3% (1)

Why each option

The question asks to identify the specific phase within the Department of Defense Information Assurance Certification and Accreditation Process (DIACAP) where residual risk is analyzed.

APhase 2

Phase 2 ('Develop and Document DIACAP') focuses on developing the system's security plan and establishing security requirements.

BPhase 4Correct

DIACAP Phase 4 is 'Make Accreditation Determination and Authorize System.' During this phase, the certifying authority provides a certification report and recommendation to the Designated Approving Authority (DAA), who then reviews the entire package, including the Plan of Action and Milestones (POAM) and the remaining (residual) risks, to make the final authorization decision.

CPhase 5

Phase 5 ('Maintain Authorization') involves continuous monitoring and managing changes to the system post-authorization.

DPhase 3

Phase 3 ('Implement and Validate IA Controls') involves implementing and testing the security controls.

EPhase 1

Phase 1 ('Initiate and Plan DIACAP') involves registering the system and defining the scope.

Concept tested: DIACAP phases and residual risk analysis

Topics

#DIACAP#Residual Risk#Risk Analysis#Compliance Maintenance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice