nerdexam
(ISC)2

CSSLP · Question #147

You work as a security engineer for BlueWell Inc. According to you, which of the following DITSCAP/NIACAP model phases occurs at the initiation of the project, or at the initial C&A effort of a legacy

The correct answer is B. Definition. In the DITSCAP/NIACAP model, the Definition phase occurs at the initiation of a project or at the beginning of an initial C&A effort for a legacy system.

Secure Software Lifecycle Management

Question

You work as a security engineer for BlueWell Inc. According to you, which of the following DITSCAP/NIACAP model phases occurs at the initiation of the project, or at the initial C&A effort of a legacy system?

Options

  • AValidation
  • BDefinition
  • CVerification
  • DPost Accreditation

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    92% (47)
  • C
    2% (1)
  • D
    2% (1)

Why each option

In the DITSCAP/NIACAP model, the Definition phase occurs at the initiation of a project or at the beginning of an initial C&A effort for a legacy system.

AValidation

Validation is a later phase where security controls are assessed to ensure they meet requirements and are implemented correctly.

BDefinitionCorrect

The DITSCAP (Defense Information Technology Security Certification and Accreditation Process) and NIACAP (National Information Assurance Certification and Accreditation Process) models both start with the Definition phase. This initial phase involves establishing the C&A scope, identifying the system's mission, criticality, and security requirements, essentially defining the project's security baseline.

CVerification

Verification is also a later phase, closely related to validation, where the system's security posture is confirmed through testing and evaluation.

DPost Accreditation

Post Accreditation is the final, ongoing phase, dealing with continuous monitoring and maintenance of the system's accreditation status.

Concept tested: DITSCAP-NIACAP phases - Definition

Source: https://www.cnss.gov/cnss/Assets/pdf/nstissi_1000_12.pdf

Topics

#DITSCAP#NIACAP#Certification and Accreditation (C&A)#Security lifecycle models

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice