nerdexam
(ISC)2

CGRC · Question #229

In which of the following phases of the DITSCAP process does Security Test and Evaluation (ST&E) occur? Response:

The correct answer is B. Phase 3. Security Test and Evaluation (ST&E) is a crucial activity that takes place during Phase 3, the Certification Phase, of the Department of Defense Information Technology Security Certification and Accreditation Process (DITSCAP).

Assessment/Audit of Security and Privacy Controls

Question

In which of the following phases of the DITSCAP process does Security Test and Evaluation (ST&E) occur? Response:

Options

  • APhase 2
  • BPhase 3
  • CPhase 1
  • DPhase 4

How the community answered

(28 responses)
  • B
    89% (25)
  • C
    4% (1)
  • D
    7% (2)

Why each option

Security Test and Evaluation (ST&E) is a crucial activity that takes place during Phase 3, the Certification Phase, of the Department of Defense Information Technology Security Certification and Accreditation Process (DITSCAP).

APhase 2

Phase 2 (Definition) focuses on defining the system security requirements and developing the security plan, not performing ST&E.

BPhase 3Correct

Phase 3 of DITSCAP is known as the Certification Phase, where formal testing and evaluation activities, including Security Test and Evaluation (ST&E), are conducted to verify the system's compliance with security requirements and its effectiveness.

CPhase 1

Phase 1 (Initiation) involves identifying the mission and system characteristics, and determining the DITSCAP scope.

DPhase 4

Phase 4 (Accreditation) involves the Designated Approving Authority (DAA) making the final accreditation decision based on the certification results and overall risk.

Concept tested: DITSCAP phases and ST&E

Topics

#DITSCAP#Security Test and Evaluation#Certification and Accreditation#System Assessment

Community Discussion

No community discussion yet for this question.

Full CGRC Practice