CSSLP · Question #205
The Phase 3 of DITSCAP C&A is known as Validation. The goal of Phase 3 is to validate that the preceding work has produced an IS that operates in a specified computing environment. What are the proces
The correct answer is A. Certification and accreditation decision B. Continue to review and refine the SSAA C. Perform certification evaluation of the integrated system E. Develop recommendation to the DAA. Phase 3 (Validation) of DITSCAP C&A involves evaluating the integrated system, refining the System Security Authorization Agreement (SSAA), developing accreditation recommendations, and making the final certification and accreditation decision.
Question
The Phase 3 of DITSCAP C&A is known as Validation. The goal of Phase 3 is to validate that the preceding work has produced an IS that operates in a specified computing environment. What are the process activities of this phase? Each correct answer represents a complete solution. Choose all that apply.
Options
- ACertification and accreditation decision
- BContinue to review and refine the SSAA
- CPerform certification evaluation of the integrated system
- DSystem development
- EDevelop recommendation to the DAA
How the community answered
(25 responses)- A88% (22)
- D12% (3)
Why each option
Phase 3 (Validation) of DITSCAP C&A involves evaluating the integrated system, refining the System Security Authorization Agreement (SSAA), developing accreditation recommendations, and making the final certification and accreditation decision.
The ultimate outcome of the DITSCAP C&A process, following validation, is the certification and accreditation decision, which is finalized in Phase 3.
The System Security Authorization Agreement (SSAA) is a living document that is continuously reviewed and refined throughout the DITSCAP phases, including Validation, to reflect the current state of the system and its security posture.
A core activity of the Validation phase is to perform a comprehensive certification evaluation of the integrated system to ensure it meets security requirements and operates as specified.
System development is part of an earlier phase of the DITSCAP process (Phase 2 - Definition), where the system is designed and built, not a primary activity of the Validation phase.
Developing a recommendation to the Designated Approving Authority (DAA) is a crucial step in Phase 3, where the certifier presents findings and suggests whether the system should be accredited.
Concept tested: DITSCAP Certification and Accreditation (C&A) phases
Topics
Community Discussion
No community discussion yet for this question.