CSSLP · Question #2
The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems t
The correct answer is A. Certification agent B. Designated Approving Authority C. IS program manager E. User representative. The National Information Assurance Certification and Accreditation Process (NIACAP) requires key participants like the Certification Agent, Designated Approving Authority, IS Program Manager, and User Representative to ensure comprehensive security assessment and accreditation.
Question
The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems that handle U.S. national security information. Which of the following participants are required in a NIACAP security assessment? Each correct answer represents a part of the solution. Choose all that apply.
Options
- ACertification agent
- BDesignated Approving Authority
- CIS program manager
- DInformation Assurance Manager
- EUser representative
How the community answered
(25 responses)- A92% (23)
- D8% (2)
Why each option
The National Information Assurance Certification and Accreditation Process (NIACAP) requires key participants like the Certification Agent, Designated Approving Authority, IS Program Manager, and User Representative to ensure comprehensive security assessment and accreditation.
The Certification Agent is responsible for conducting the technical evaluation of the system's security posture and providing a certification report.
The Designated Approving Authority (DAA) is the senior management official who makes the final decision to accept the residual risk and formally accredit the system.
The IS program manager (or System Manager) is responsible for the overall management and security of the information system throughout its lifecycle.
While an Information Assurance Manager (IAM) is a crucial role in information security, the NIACAP framework specifically lists Certification Agent, DAA, Program/System Manager, and User Representative as the required direct participants in the assessment and accreditation decisions.
The User Representative provides input on operational requirements and the impact of security controls on the end-user community.
Concept tested: NIACAP roles and responsibilities
Source: https://www.dni.gov/files/documents/NIACAP_Manual_Final_v1_0_1997.pdf
Topics
Community Discussion
No community discussion yet for this question.