nerdexam
(ISC)2

CSSLP · Question #295

The Phase 2 of DITSCAP C&A is known as Verification. The goal of this phase is to obtain a fully integrated system for certification testing and accreditation. What are the process activities of this

The correct answer is A. Certification analysis B. Assessment of the Analysis Results C. Configuring refinement of the SSAA D. System development. The Verification phase (Phase 2) of DITSCAP C&A includes key activities such as certification analysis, assessment of analysis results, refining the SSAA configuration, and system development to integrate the system for testing.

Secure Software Lifecycle Management

Question

The Phase 2 of DITSCAP C&A is known as Verification. The goal of this phase is to obtain a fully integrated system for certification testing and accreditation. What are the process activities of this phase? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ACertification analysis
  • BAssessment of the Analysis Results
  • CConfiguring refinement of the SSAA
  • DSystem development
  • ERegistration

How the community answered

(53 responses)
  • A
    91% (48)
  • E
    9% (5)

Why each option

The Verification phase (Phase 2) of DITSCAP C&A includes key activities such as certification analysis, assessment of analysis results, refining the SSAA configuration, and system development to integrate the system for testing.

ACertification analysisCorrect

Certification analysis is a key activity in the Verification phase, involving a detailed examination of the system's security controls and their implementation to determine compliance with security requirements.

BAssessment of the Analysis ResultsCorrect

Assessment of the Analysis Results involves reviewing the outcomes of the certification analysis to identify any gaps or non-compliance issues before proceeding to accreditation.

CConfiguring refinement of the SSAACorrect

Configuring refinement of the System Security Accreditation Agreement (SSAA) involves updating and refining the security plan based on findings from the analysis and assessment, ensuring it accurately reflects the system's security posture.

DSystem developmentCorrect

System development, particularly in an iterative sense within the C&A lifecycle, can occur as part of this phase to implement or refine security controls identified during analysis and assessment, aiming for a fully integrated and secure system.

ERegistration

Registration is typically part of the initial or final steps (e.g., registering the system for accreditation or registering the accreditation status), but not a core 'process activity' within the Verification phase focused on building and testing the system.

Concept tested: DITSCAP C&A Verification phase activities

Topics

#DITSCAP#Certification and Accreditation (C&A)#Verification phase#Security assessment

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice