nerdexam
(ISC)2

CSSLP · Question #205

The Phase 3 of DITSCAP C&A is known as Validation. The goal of Phase 3 is to validate that the preceding work has produced an IS that operates in a specified computing environment. What are the proces

The correct answer is A. Certification and accreditation decision B. Continue to review and refine the SSAA C. Perform certification evaluation of the integrated system E. Develop recommendation to the DAA. Phase 3 (Validation) of DITSCAP C&A involves evaluating the integrated system, refining the System Security Authorization Agreement (SSAA), developing accreditation recommendations, and making the final certification and accreditation decision.

Secure Software Deployment, Operations, Maintenance

Question

The Phase 3 of DITSCAP C&A is known as Validation. The goal of Phase 3 is to validate that the preceding work has produced an IS that operates in a specified computing environment. What are the process activities of this phase? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ACertification and accreditation decision
  • BContinue to review and refine the SSAA
  • CPerform certification evaluation of the integrated system
  • DSystem development
  • EDevelop recommendation to the DAA

How the community answered

(25 responses)
  • A
    88% (22)
  • D
    12% (3)

Why each option

Phase 3 (Validation) of DITSCAP C&A involves evaluating the integrated system, refining the System Security Authorization Agreement (SSAA), developing accreditation recommendations, and making the final certification and accreditation decision.

ACertification and accreditation decisionCorrect

The ultimate outcome of the DITSCAP C&A process, following validation, is the certification and accreditation decision, which is finalized in Phase 3.

BContinue to review and refine the SSAACorrect

The System Security Authorization Agreement (SSAA) is a living document that is continuously reviewed and refined throughout the DITSCAP phases, including Validation, to reflect the current state of the system and its security posture.

CPerform certification evaluation of the integrated systemCorrect

A core activity of the Validation phase is to perform a comprehensive certification evaluation of the integrated system to ensure it meets security requirements and operates as specified.

DSystem development

System development is part of an earlier phase of the DITSCAP process (Phase 2 - Definition), where the system is designed and built, not a primary activity of the Validation phase.

EDevelop recommendation to the DAACorrect

Developing a recommendation to the Designated Approving Authority (DAA) is a crucial step in Phase 3, where the certifier presents findings and suggests whether the system should be accredited.

Concept tested: DITSCAP Certification and Accreditation (C&A) phases

Topics

#DITSCAP#Certification and Accreditation (C&A)#Validation Phase#System Security Authorization Agreement (SSAA)

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice