nerdexam
(ISC)2

CGRC · Question #577

Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or a

The correct answer is A. Accreditation is the official management decision given by a senior agency official to authorize B. Certification is a comprehensive assessment of the management, operational, and technical. Certification is the technical assessment and evaluation of a system's security, while Accreditation is the formal management decision to authorize system operation based on that assessment. These two components are distinct yet interdependent processes in securing information sy

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation? Each correct answer represents a complete solution. Choose two. Response:

Options

  • AAccreditation is the official management decision given by a senior agency official to authorize
  • BCertification is a comprehensive assessment of the management, operational, and technical
  • CAccreditation is a comprehensive assessment of the management, operational, and technical
  • DCertification is the official management decision given by a senior agency official to authorize

How the community answered

(19 responses)
  • A
    84% (16)
  • C
    5% (1)
  • D
    11% (2)

Why each option

Certification is the technical assessment and evaluation of a system's security, while Accreditation is the formal management decision to authorize system operation based on that assessment. These two components are distinct yet interdependent processes in securing information systems.

AAccreditation is the official management decision given by a senior agency official to authorizeCorrect

Accreditation is indeed the official management decision, made by a senior agency official (the Authorizing Official), to accept the residual risk and authorize an information system to operate.

BCertification is a comprehensive assessment of the management, operational, and technicalCorrect

Certification is the comprehensive technical, management, and operational assessment of an information system's security controls to determine if they are implemented correctly, operating as intended, and meeting security requirements.

CAccreditation is a comprehensive assessment of the management, operational, and technical

This statement incorrectly defines Accreditation as the 'comprehensive assessment'; that description belongs to Certification.

DCertification is the official management decision given by a senior agency official to authorize

This statement incorrectly defines Certification as the 'official management decision'; that description belongs to Accreditation.

Concept tested: Certification vs. Accreditation definitions

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Certification#Accreditation#Risk Management Framework (RMF)#Authorization to Operate (ATO)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice