CSSLP · Question #290
Which of the following describes a residual risk as the risk remaining after a risk mitigation has occurred?
The correct answer is A. DIACAP. DIACAP (Department of Defense Information Assurance Certification and Accreditation Process) is a framework that specifically describes residual risk as the risk remaining after mitigation efforts have been applied.
Question
Which of the following describes a residual risk as the risk remaining after a risk mitigation has occurred?
Options
- ADIACAP
- BSSAA
- CDAA
- DISSO
How the community answered
(40 responses)- A93% (37)
- C3% (1)
- D5% (2)
Why each option
DIACAP (Department of Defense Information Assurance Certification and Accreditation Process) is a framework that specifically describes residual risk as the risk remaining after mitigation efforts have been applied.
DIACAP (Department of Defense Information Assurance Certification and Accreditation Process) explicitly includes the concept of residual risk, which is the level of risk remaining after security controls and mitigation strategies have been applied. It's a key part of its risk management framework to evaluate the remaining risk post-mitigation.
SSAA (System Security Accreditation Agreement) is a document outlining an agreement, not a process that describes residual risk in general terms.
DAA (Designated Approving Authority) is an individual responsible for making accreditation decisions, not a framework or description of residual risk.
ISSO (Information System Security Officer) is a role responsible for security, not a process or definition of residual risk.
Concept tested: Definition of residual risk in security frameworks
Topics
Community Discussion
No community discussion yet for this question.