nerdexam
(ISC)2

CSSLP · Question #26

Which of the following processes culminates in an agreement between key players that a system in its current configuration and operation provides adequate protection controls?

The correct answer is C. Certification and accreditation (C&A). Certification and Accreditation (C&A) is the process that culminates in an agreement between key players that a system provides adequate protection controls in its current configuration and operation.

Secure Software Deployment, Operations, Maintenance

Question

Which of the following processes culminates in an agreement between key players that a system in its current configuration and operation provides adequate protection controls?

Options

  • AInformation Assurance (IA)
  • BInformation systems security engineering (ISSE)
  • CCertification and accreditation (C&A)
  • DRisk Management

How the community answered

(57 responses)
  • A
    2% (1)
  • B
    5% (3)
  • C
    91% (52)
  • D
    2% (1)

Why each option

Certification and Accreditation (C&A) is the process that culminates in an agreement between key players that a system provides adequate protection controls in its current configuration and operation.

AInformation Assurance (IA)

Information Assurance (IA) is a broader concept encompassing the measures taken to protect and defend information and information systems, rather than a specific process culminating in system approval.

BInformation systems security engineering (ISSE)

Information systems security engineering (ISSE) is the process of integrating security into the system development lifecycle, focusing on design and implementation throughout the engineering phases.

CCertification and accreditation (C&A)Correct

Certification and Accreditation (C&A) is a formal process involving a technical evaluation (certification) of a system's security controls, followed by a management decision (accreditation) by a designated official to authorize the system to operate based on an acceptable level of residual risk.

DRisk Management

Risk Management is the overall process of identifying, assessing, and mitigating risks to an organization's assets, which is a continuous activity and a fundamental component of C&A, but not the final agreement itself.

Concept tested: System security Certification and Accreditation (C&A)

Source: https://csrc.nist.gov/glossary/term/certification_and_accreditation

Topics

#Certification and Accreditation#System Authorization#Security Controls

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice