nerdexam
(ISC)2

CSSLP · Question #121

Which of the following phases of the DITSCAP C&A process is used to define the C&A level of effort, to identify the main C&A roles and responsibilities, and to create an agreement on the method for im

The correct answer is A. Phase 1. Phase 1 of the DITSCAP C&A process, known as 'Definition,' is where the scope, roles, responsibilities, and overall approach for implementing security requirements are established.

Secure Software Lifecycle Management

Question

Which of the following phases of the DITSCAP C&A process is used to define the C&A level of effort, to identify the main C&A roles and responsibilities, and to create an agreement on the method for implementing the security requirements?

Options

  • APhase 1
  • BPhase 4
  • CPhase 2
  • DPhase 3

How the community answered

(41 responses)
  • A
    93% (38)
  • C
    5% (2)
  • D
    2% (1)

Why each option

Phase 1 of the DITSCAP C&A process, known as 'Definition,' is where the scope, roles, responsibilities, and overall approach for implementing security requirements are established.

APhase 1Correct

Phase 1, the 'Definition' phase of DITSCAP, is precisely where the C&A level of effort is determined, main C&A roles and responsibilities are identified, and an agreement on the method for implementing the security requirements is created. This initial phase sets the groundwork and planning for the entire certification and accreditation process.

BPhase 4

Phase 4 ('Post Accreditation') involves continuous monitoring and managing changes after a system has been accredited, not the initial planning and definition.

CPhase 2

Phase 2 ('Verification') involves testing and verifying the security implementation and controls, which occurs after the initial definition and planning stage.

DPhase 3

Phase 3 ('Validation') involves the formal review and approval process for the system's security posture, following the verification of controls.

Concept tested: DITSCAP Certification and Accreditation phases

Topics

#DITSCAP#Certification and Accreditation (C&A)#Security Governance#Security Frameworks

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice