CSSLP · Question #147
You work as a security engineer for BlueWell Inc. According to you, which of the following DITSCAP/NIACAP model phases occurs at the initiation of the project, or at the initial C&A effort of a legacy
The correct answer is B. Definition. In the DITSCAP/NIACAP model, the Definition phase occurs at the initiation of a project or at the beginning of an initial C&A effort for a legacy system.
Question
You work as a security engineer for BlueWell Inc. According to you, which of the following DITSCAP/NIACAP model phases occurs at the initiation of the project, or at the initial C&A effort of a legacy system?
Options
- AValidation
- BDefinition
- CVerification
- DPost Accreditation
How the community answered
(51 responses)- A4% (2)
- B92% (47)
- C2% (1)
- D2% (1)
Why each option
In the DITSCAP/NIACAP model, the Definition phase occurs at the initiation of a project or at the beginning of an initial C&A effort for a legacy system.
Validation is a later phase where security controls are assessed to ensure they meet requirements and are implemented correctly.
The DITSCAP (Defense Information Technology Security Certification and Accreditation Process) and NIACAP (National Information Assurance Certification and Accreditation Process) models both start with the Definition phase. This initial phase involves establishing the C&A scope, identifying the system's mission, criticality, and security requirements, essentially defining the project's security baseline.
Verification is also a later phase, closely related to validation, where the system's security posture is confirmed through testing and evaluation.
Post Accreditation is the final, ongoing phase, dealing with continuous monitoring and maintenance of the system's accreditation status.
Concept tested: DITSCAP-NIACAP phases - Definition
Source: https://www.cnss.gov/cnss/Assets/pdf/nstissi_1000_12.pdf
Topics
Community Discussion
No community discussion yet for this question.