CGRC · Question #37
Certification and Accreditation (C&A or CnA) is a process for implementing information security. Which of the following is the correct order of C&A phases in a DITSCAP assessment? Response:
The correct answer is D. Definition, Verification, Validation, and Post Accreditation. The DITSCAP (Defense Information Technology Security Certification and Accreditation Process) phases follow a specific sequence: Definition, Verification, Validation, and Post Accreditation.
Question
Certification and Accreditation (C&A or CnA) is a process for implementing information security. Which of the following is the correct order of C&A phases in a DITSCAP assessment? Response:
Options
- ADefinition, Validation, Verification, and Post Accreditation
- BVerification, Definition, Validation, and Post Accreditation
- CVerification, Validation, Definition, and Post Accreditation
- DDefinition, Verification, Validation, and Post Accreditation
How the community answered
(53 responses)- B2% (1)
- C4% (2)
- D94% (50)
Why each option
The DITSCAP (Defense Information Technology Security Certification and Accreditation Process) phases follow a specific sequence: Definition, Verification, Validation, and Post Accreditation.
This order is incorrect as Verification precedes Validation in DITSCAP.
This order is incorrect as Definition is the initial phase, not Verification.
This order is incorrect as Definition is the initial phase, and the order of Verification and Validation is swapped.
The DITSCAP (Defense Information Technology Security Certification and Accreditation Process) defines four distinct phases for C&A: 1) Definition (establishing system boundaries and security requirements), 2) Verification (technical assessment of security controls), 3) Validation (management review and risk acceptance), and 4) Post Accreditation (continuous monitoring and maintenance).
Concept tested: DITSCAP phases for C&A
Topics
Community Discussion
No community discussion yet for this question.