nerdexam
(ISC)2

CSSLP · Question #29

Which of the following DITSCAP C&A phases takes place between the signing of the initial version of the SSAA and the formal accreditation of the system?

The correct answer is D. Phase 2. In the DITSCAP framework, Phase 2, known as 'Verification,' occurs between the signing of the initial System Security Authorization Agreement (SSAA) and the formal accreditation of the system.

Secure Software Lifecycle Management

Question

Which of the following DITSCAP C&A phases takes place between the signing of the initial version of the SSAA and the formal accreditation of the system?

Options

  • APhase 4
  • BPhase 3
  • CPhase 1
  • DPhase 2

How the community answered

(38 responses)
  • B
    3% (1)
  • C
    3% (1)
  • D
    95% (36)

Why each option

In the DITSCAP framework, Phase 2, known as 'Verification,' occurs between the signing of the initial System Security Authorization Agreement (SSAA) and the formal accreditation of the system.

APhase 4

Phase 4, 'Post-Accreditation,' occurs after the system has received formal accreditation, focusing on continuous monitoring, re-evaluation, and eventual re-accreditation.

BPhase 3

Phase 3, 'Validation,' is the phase where the system's security posture is validated, and the accreditation package is prepared and presented for the formal accreditation decision.

CPhase 1

Phase 1, 'Definition,' involves defining the system's security requirements, policies, and the initial development of the System Security Authorization Agreement (SSAA).

DPhase 2Correct

DITSCAP Phase 2, 'Verification,' is the stage where the implemented security controls are verified for their effectiveness, and the system is assessed against its security requirements, leading up to the final accreditation decision.

Concept tested: DITSCAP phases

Topics

#DITSCAP#Certification and Accreditation (C&A)#SSAA#Security Phases

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice