nerdexam
(ISC)2

CSSLP · Question #100

The IAM/CA makes certification accreditation recommendations to the DAA. The DAA issues accreditation determinations. Which of the following are the accreditation determinations issued by the DAA? Eac

The correct answer is A. IATT B. IATO C. DATO D. ATO. The Designated Approving Authority (DAA) issues various accreditation determinations as part of the Certification and Accreditation (C&A) process, which include both interim and final authorizations to operate or test.

Secure Software Deployment, Operations, Maintenance

Question

The IAM/CA makes certification accreditation recommendations to the DAA. The DAA issues accreditation determinations. Which of the following are the accreditation determinations issued by the DAA? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AIATT
  • BIATO
  • CDATO
  • DATO
  • EATT

How the community answered

(22 responses)
  • A
    86% (19)
  • E
    14% (3)

Why each option

The Designated Approving Authority (DAA) issues various accreditation determinations as part of the Certification and Accreditation (C&A) process, which include both interim and final authorizations to operate or test.

AIATTCorrect

IATT (Interim Authorization to Test) is an interim decision that formally permits the testing of a system under specific conditions.

BIATOCorrect

IATO (Interim Authorization to Operate) is an interim decision allowing a system to operate under specific conditions for a limited time, pending a full Authorization to Operate (ATO).

CDATOCorrect

DATO (Denial of Authorization to Operate) is a formal decision to not allow a system to operate due to identified unacceptable risks.

DATOCorrect

ATO (Authorization to Operate) is a formal decision by a DAA to permit a system to operate for a specified period, indicating the system's security posture is acceptable.

EATT

ATT (Authorization to Test) is not a standard, formal accreditation determination term used by a DAA in the context of government or military C&A processes; IATT serves as the interim authorization for testing activities.

Concept tested: Certification and Accreditation (C&A) determinations

Source: https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-fedramp

Topics

#Accreditation#Authorization to Operate (ATO)#Risk Management Framework (RMF)#Deployment Security

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice