CGRC · Question #618
Which of the following processes provides a standard set of activities, general tasks, and a management structure to certify and accredit systems, which maintain the information assurance and the…
The correct answer is B. NIACAP. The National Information Assurance Certification and Accreditation Process (NIACAP) was a framework that provided a standard set of activities and a management structure for certifying and accrediting systems. Its purpose was to maintain the information assurance and security…
Question
Which of the following processes provides a standard set of activities, general tasks, and a management structure to certify and accredit systems, which maintain the information assurance and the security posture of a system or site? Response:
Options
- ADITSCAP
- BNIACAP
- CNSA-IAM
- DASSET
How the community answered
(23 responses)- A4% (1)
- B96% (22)
Why each option
The National Information Assurance Certification and Accreditation Process (NIACAP) was a framework that provided a standard set of activities and a management structure for certifying and accrediting systems. Its purpose was to maintain the information assurance and security posture of federal systems.
DITSCAP (Department of Defense Information Technology Security Certification and Accreditation Process) was a DoD-specific framework, not a general federal one like NIACAP.
The National Information Assurance Certification and Accreditation Process (NIACAP) was a U.S. federal government process designed to provide a uniform approach to certifying and accrediting information systems. It established a standard set of activities and a management structure to maintain information assurance and the security posture of systems or sites.
NSA-IAM (Information Assurance Methodology) is a methodology for assessing security, not a comprehensive C&A process.
ASSET is not a recognized certification and accreditation process in this context.
Concept tested: Legacy Certification and Accreditation frameworks
Topics
Community Discussion
No community discussion yet for this question.