CGRC · Question #405
Which of the following is used throughout the entire C&A process? Response:
The correct answer is C. SSAA. The System Security Authorization Agreement (SSAA) is used throughout the entire Certification and Accreditation (C&A) process, serving as the foundational document that defines the scope, requirements, and responsibilities for system security. It provides continuity and…
Question
Which of the following is used throughout the entire C&A process? Response:
Options
- ADAA
- BDITSCAP
- CSSAA
- DDIACAP
How the community answered
(34 responses)- A3% (1)
- C94% (32)
- D3% (1)
Why each option
The System Security Authorization Agreement (SSAA) is used throughout the entire Certification and Accreditation (C&A) process, serving as the foundational document that defines the scope, requirements, and responsibilities for system security. It provides continuity and guidance from initiation through authorization.
DAA (Designated Approving Authority) is a role, not a document or process used throughout the C&A, although the DAA is involved in authorization.
DITSCAP (Defense Information Technology Security Certification and Accreditation Process) was a C&A framework, but it is a process itself, not a single artifact used throughout a generic C&A.
The System Security Authorization Agreement (SSAA) is a comprehensive document developed early in the C&A process and is continuously updated and referenced throughout the entire lifecycle. It formally documents the agreements among various parties regarding the security requirements, controls, and responsibilities for the system undergoing C&A.
DIACAP (Department of Defense Information Assurance Certification and Accreditation Process) is a framework that replaced DITSCAP, similar to DITSCAP, it is the process itself rather than a single document used throughout.
Concept tested: C&A process documents
Topics
Community Discussion
No community discussion yet for this question.