CGRC · Question #497
Which of the following refers to an information security document that is used in the United States Department of Defense (DoD) to describe and accredit networks and systems? Response:
The correct answer is D. SSAA. The System Security Authorization Agreement (SSAA) was a specific Department of Defense (DoD) document historically used to describe, manage, and accredit information networks and systems. It outlined the security posture and served as the basis for authorization to operate for…
Question
Which of the following refers to an information security document that is used in the United States Department of Defense (DoD) to describe and accredit networks and systems? Response:
Options
- AFITSAF
- BFIPS
- CTCSEC
- DSSAA
How the community answered
(36 responses)- A6% (2)
- B3% (1)
- D92% (33)
Why each option
The System Security Authorization Agreement (SSAA) was a specific Department of Defense (DoD) document historically used to describe, manage, and accredit information networks and systems. It outlined the security posture and served as the basis for authorization to operate for DoD systems.
FITSAF (Federal Information Technology Security Assessment Framework) is not a standard DoD accreditation document.
FIPS (Federal Information Processing Standards) are publications by NIST that define standards, not an accreditation document itself.
TCSEC (Trusted Computer System Evaluation Criteria) was an old DoD standard for evaluating computer system security, not an accreditation document for networks and systems.
The System Security Authorization Agreement (SSAA) was a document used within the Department of Defense (DoD) to formally document the security posture of an information system or network and serve as the basis for its accreditation or authorization to operate. While superseded by other processes like DIACAP and now RMF, the SSAA was historically the correct answer for DoD accreditation documents.
Concept tested: DoD Accreditation Documents, SSAA
Topics
Community Discussion
No community discussion yet for this question.