CGRC · Question #124
Which of the following refers to a process that is used for implementing information security? Response:
The correct answer is A. Certification and Accreditation (C&A). Certification and Accreditation (C&A) is a formal process used for implementing information security by assessing and authorizing systems to operate based on their security posture.
Question
Which of the following refers to a process that is used for implementing information security? Response:
Options
- ACertification and Accreditation (C&A)
- BInformation Assurance (IA)
- CFive Pillars model
- DClassic information security model
How the community answered
(21 responses)- A86% (18)
- B5% (1)
- C10% (2)
Why each option
Certification and Accreditation (C&A) is a formal process used for implementing information security by assessing and authorizing systems to operate based on their security posture.
Certification and Accreditation (C&A) is a structured process involving the technical evaluation (certification) of an information system's security controls, followed by a formal management decision (accreditation) by an Authorizing Official (AO) to allow the system to operate. This process ensures that security risks are identified, assessed, and managed.
Information Assurance (IA) is a broader concept encompassing the protection of information systems, but it is not a specific process for implementation itself.
The 'Five Pillars model' is not a recognized, standard process for implementing information security.
The 'Classic information security model' usually refers to the CIA triad (Confidentiality, Integrity, Availability), which describes security goals, not a process for implementation.
Concept tested: Information security implementation process
Source: https://csrc.nist.gov/glossary/term/certification_and_accreditation
Topics
Community Discussion
No community discussion yet for this question.