nerdexam
(ISC)2

CGRC · Question #124

Which of the following refers to a process that is used for implementing information security? Response:

The correct answer is A. Certification and Accreditation (C&A). Certification and Accreditation (C&A) is a formal process used for implementing information security by assessing and authorizing systems to operate based on their security posture.

Implementation of Security and Privacy Controls

Question

Which of the following refers to a process that is used for implementing information security? Response:

Options

  • ACertification and Accreditation (C&A)
  • BInformation Assurance (IA)
  • CFive Pillars model
  • DClassic information security model

How the community answered

(21 responses)
  • A
    86% (18)
  • B
    5% (1)
  • C
    10% (2)

Why each option

Certification and Accreditation (C&A) is a formal process used for implementing information security by assessing and authorizing systems to operate based on their security posture.

ACertification and Accreditation (C&A)Correct

Certification and Accreditation (C&A) is a structured process involving the technical evaluation (certification) of an information system's security controls, followed by a formal management decision (accreditation) by an Authorizing Official (AO) to allow the system to operate. This process ensures that security risks are identified, assessed, and managed.

BInformation Assurance (IA)

Information Assurance (IA) is a broader concept encompassing the protection of information systems, but it is not a specific process for implementation itself.

CFive Pillars model

The 'Five Pillars model' is not a recognized, standard process for implementing information security.

DClassic information security model

The 'Classic information security model' usually refers to the CIA triad (Confidentiality, Integrity, Availability), which describes security goals, not a process for implementation.

Concept tested: Information security implementation process

Source: https://csrc.nist.gov/glossary/term/certification_and_accreditation

Topics

#Certification and Accreditation (C&A)#Information Security Processes#Risk Management Framework (RMF)#System Authorization

Community Discussion

No community discussion yet for this question.

Full CGRC Practice