CGRC · Question #577
Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or a
The correct answer is A. Accreditation is the official management decision given by a senior agency official to authorize B. Certification is a comprehensive assessment of the management, operational, and technical. Certification is the technical assessment and evaluation of a system's security, while Accreditation is the formal management decision to authorize system operation based on that assessment. These two components are distinct yet interdependent processes in securing information sy
Question
Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation? Each correct answer represents a complete solution. Choose two. Response:
Options
- AAccreditation is the official management decision given by a senior agency official to authorize
- BCertification is a comprehensive assessment of the management, operational, and technical
- CAccreditation is a comprehensive assessment of the management, operational, and technical
- DCertification is the official management decision given by a senior agency official to authorize
How the community answered
(19 responses)- A84% (16)
- C5% (1)
- D11% (2)
Why each option
Certification is the technical assessment and evaluation of a system's security, while Accreditation is the formal management decision to authorize system operation based on that assessment. These two components are distinct yet interdependent processes in securing information systems.
Accreditation is indeed the official management decision, made by a senior agency official (the Authorizing Official), to accept the residual risk and authorize an information system to operate.
Certification is the comprehensive technical, management, and operational assessment of an information system's security controls to determine if they are implemented correctly, operating as intended, and meeting security requirements.
This statement incorrectly defines Accreditation as the 'comprehensive assessment'; that description belongs to Certification.
This statement incorrectly defines Certification as the 'official management decision'; that description belongs to Accreditation.
Concept tested: Certification vs. Accreditation definitions
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.