nerdexam
(ISC)2

CGRC · Question #515

Which of the following is NOT a phase of the security certification and accreditation process? Response:

The correct answer is C. Operation. The security certification and accreditation process typically includes phases like initiation, security certification, and maintenance, but 'Operation' itself is not a distinct phase within this framework.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following is NOT a phase of the security certification and accreditation process? Response:

Options

  • AInitiation
  • BSecurity certification
  • COperation
  • DMaintenance

How the community answered

(40 responses)
  • B
    3% (1)
  • C
    93% (37)
  • D
    5% (2)

Why each option

The security certification and accreditation process typically includes phases like initiation, security certification, and maintenance, but 'Operation' itself is not a distinct phase within this framework.

AInitiation

Initiation is a foundational phase where the system is defined, its boundaries are established, and initial risk assessments are performed.

BSecurity certification

Security certification (or Assess in RMF) is a critical phase where security controls are evaluated to determine their effectiveness.

COperationCorrect

The security certification and accreditation (C&A) or more broadly, the Risk Management Framework (RMF) process, does not typically list 'Operation' as one of its distinct phases. Instead, security controls are operated throughout the system lifecycle, and the 'Monitor' phase of RMF encompasses ongoing security posture awareness during the operational state.

DMaintenance

Maintenance (or Monitor in RMF) is an ongoing phase involving continuous monitoring of security controls, system changes, and risk posture.

Concept tested: Phases of Security Certification and Accreditation (C&A)/RMF

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Security Certification and Accreditation#C&A Process Phases#Risk Management Framework

Community Discussion

No community discussion yet for this question.

Full CGRC Practice