nerdexam
(ISC)2

CGRC · Question #497

Which of the following refers to an information security document that is used in the United States Department of Defense (DoD) to describe and accredit networks and systems? Response:

The correct answer is D. SSAA. The System Security Authorization Agreement (SSAA) was a specific Department of Defense (DoD) document historically used to describe, manage, and accredit information networks and systems. It outlined the security posture and served as the basis for authorization to operate for…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following refers to an information security document that is used in the United States Department of Defense (DoD) to describe and accredit networks and systems? Response:

Options

  • AFITSAF
  • BFIPS
  • CTCSEC
  • DSSAA

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    3% (1)
  • D
    92% (33)

Why each option

The System Security Authorization Agreement (SSAA) was a specific Department of Defense (DoD) document historically used to describe, manage, and accredit information networks and systems. It outlined the security posture and served as the basis for authorization to operate for DoD systems.

AFITSAF

FITSAF (Federal Information Technology Security Assessment Framework) is not a standard DoD accreditation document.

BFIPS

FIPS (Federal Information Processing Standards) are publications by NIST that define standards, not an accreditation document itself.

CTCSEC

TCSEC (Trusted Computer System Evaluation Criteria) was an old DoD standard for evaluating computer system security, not an accreditation document for networks and systems.

DSSAACorrect

The System Security Authorization Agreement (SSAA) was a document used within the Department of Defense (DoD) to formally document the security posture of an information system or network and serve as the basis for its accreditation or authorization to operate. While superseded by other processes like DIACAP and now RMF, the SSAA was historically the correct answer for DoD accreditation documents.

Concept tested: DoD Accreditation Documents, SSAA

Topics

#DoD Authorization#System Security Authorization Agreement (SSAA)#Accreditation#Information Security Documentation

Community Discussion

No community discussion yet for this question.

Full CGRC Practice