nerdexam
(ISC)2

CGRC · Question #165

Which SDLC phase can use the System Authorization package to assist with decommissioning tasks for an IS? Response:

The correct answer is A. Disposition. The Disposition phase of the System Development Life Cycle (SDLC) is where information systems are retired, and the authorization package can provide crucial documentation for decommissioning tasks such as data retention, destruction, and system disposal. This ensures a secure…

Compliance Maintenance

Question

Which SDLC phase can use the System Authorization package to assist with decommissioning tasks for an IS? Response:

Options

  • ADisposition
  • BAuthorization
  • COperation
  • DRemediation

How the community answered

(45 responses)
  • A
    89% (40)
  • B
    2% (1)
  • C
    7% (3)
  • D
    2% (1)

Why each option

The Disposition phase of the System Development Life Cycle (SDLC) is where information systems are retired, and the authorization package can provide crucial documentation for decommissioning tasks such as data retention, destruction, and system disposal. This ensures a secure and compliant end-of-life process.

ADispositionCorrect

The Disposition phase is the final stage of the SDLC where an information system is retired or removed from service. The System Authorization package, which includes documentation like the System Security Plan (SSP), Security Assessment Report (SAR), and authorization decision, contains vital information about data classification, security controls, and compliance requirements. This documentation is essential for properly decommissioning the system, ensuring secure data sanitization, hardware disposal, and compliance with retention policies.

BAuthorization

The Authorization phase involves obtaining an Authority to Operate (ATO) for the system, which occurs much earlier in its lifecycle before decommissioning.

COperation

The Operation phase is where the system is actively used and maintained, preceding the decommissioning activities.

DRemediation

Remediation involves fixing identified security weaknesses, which is part of the ongoing operations or assessment phases, not directly related to decommissioning using the full authorization package.

Concept tested: SDLC phases and Authorization package use

Source: https://csrc.nist.gov/glossary/term/disposition_phase

Topics

#SDLC#Disposition Phase#Decommissioning#System Authorization

Community Discussion

No community discussion yet for this question.

Full CGRC Practice