CSSLP · Question #121
Which of the following phases of the DITSCAP C&A process is used to define the C&A level of effort, to identify the main C&A roles and responsibilities, and to create an agreement on the method for im
The correct answer is A. Phase 1. Phase 1 of the DITSCAP C&A process, known as 'Definition,' is where the scope, roles, responsibilities, and overall approach for implementing security requirements are established.
Question
Which of the following phases of the DITSCAP C&A process is used to define the C&A level of effort, to identify the main C&A roles and responsibilities, and to create an agreement on the method for implementing the security requirements?
Options
- APhase 1
- BPhase 4
- CPhase 2
- DPhase 3
How the community answered
(41 responses)- A93% (38)
- C5% (2)
- D2% (1)
Why each option
Phase 1 of the DITSCAP C&A process, known as 'Definition,' is where the scope, roles, responsibilities, and overall approach for implementing security requirements are established.
Phase 1, the 'Definition' phase of DITSCAP, is precisely where the C&A level of effort is determined, main C&A roles and responsibilities are identified, and an agreement on the method for implementing the security requirements is created. This initial phase sets the groundwork and planning for the entire certification and accreditation process.
Phase 4 ('Post Accreditation') involves continuous monitoring and managing changes after a system has been accredited, not the initial planning and definition.
Phase 2 ('Verification') involves testing and verifying the security implementation and controls, which occurs after the initial definition and planning stage.
Phase 3 ('Validation') involves the formal review and approval process for the system's security posture, following the verification of controls.
Concept tested: DITSCAP Certification and Accreditation phases
Topics
Community Discussion
No community discussion yet for this question.