nerdexam
(ISC)2

CSSLP · Question #2

The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems t

The correct answer is A. Certification agent B. Designated Approving Authority C. IS program manager E. User representative. The National Information Assurance Certification and Accreditation Process (NIACAP) requires key participants like the Certification Agent, Designated Approving Authority, IS Program Manager, and User Representative to ensure comprehensive security assessment and accreditation.

Secure Software Deployment, Operations, Maintenance

Question

The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems that handle U.S. national security information. Which of the following participants are required in a NIACAP security assessment? Each correct answer represents a part of the solution. Choose all that apply.

Options

  • ACertification agent
  • BDesignated Approving Authority
  • CIS program manager
  • DInformation Assurance Manager
  • EUser representative

How the community answered

(25 responses)
  • A
    92% (23)
  • D
    8% (2)

Why each option

The National Information Assurance Certification and Accreditation Process (NIACAP) requires key participants like the Certification Agent, Designated Approving Authority, IS Program Manager, and User Representative to ensure comprehensive security assessment and accreditation.

ACertification agentCorrect

The Certification Agent is responsible for conducting the technical evaluation of the system's security posture and providing a certification report.

BDesignated Approving AuthorityCorrect

The Designated Approving Authority (DAA) is the senior management official who makes the final decision to accept the residual risk and formally accredit the system.

CIS program managerCorrect

The IS program manager (or System Manager) is responsible for the overall management and security of the information system throughout its lifecycle.

DInformation Assurance Manager

While an Information Assurance Manager (IAM) is a crucial role in information security, the NIACAP framework specifically lists Certification Agent, DAA, Program/System Manager, and User Representative as the required direct participants in the assessment and accreditation decisions.

EUser representativeCorrect

The User Representative provides input on operational requirements and the impact of security controls on the end-user community.

Concept tested: NIACAP roles and responsibilities

Source: https://www.dni.gov/files/documents/NIACAP_Manual_Final_v1_0_1997.pdf

Topics

#NIACAP#Certification & Accreditation#Security Assessment#Roles and Responsibilities

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice