CGRC · Question #515
Which of the following is NOT a phase of the security certification and accreditation process? Response:
The correct answer is C. Operation. The security certification and accreditation process typically includes phases like initiation, security certification, and maintenance, but 'Operation' itself is not a distinct phase within this framework.
Question
Which of the following is NOT a phase of the security certification and accreditation process? Response:
Options
- AInitiation
- BSecurity certification
- COperation
- DMaintenance
How the community answered
(40 responses)- B3% (1)
- C93% (37)
- D5% (2)
Why each option
The security certification and accreditation process typically includes phases like initiation, security certification, and maintenance, but 'Operation' itself is not a distinct phase within this framework.
Initiation is a foundational phase where the system is defined, its boundaries are established, and initial risk assessments are performed.
Security certification (or Assess in RMF) is a critical phase where security controls are evaluated to determine their effectiveness.
The security certification and accreditation (C&A) or more broadly, the Risk Management Framework (RMF) process, does not typically list 'Operation' as one of its distinct phases. Instead, security controls are operated throughout the system lifecycle, and the 'Monitor' phase of RMF encompasses ongoing security posture awareness during the operational state.
Maintenance (or Monitor in RMF) is an ongoing phase involving continuous monitoring of security controls, system changes, and risk posture.
Concept tested: Phases of Security Certification and Accreditation (C&A)/RMF
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.