CSSLP · Question #295
The Phase 2 of DITSCAP C&A is known as Verification. The goal of this phase is to obtain a fully integrated system for certification testing and accreditation. What are the process activities of this
The correct answer is A. Certification analysis B. Assessment of the Analysis Results C. Configuring refinement of the SSAA D. System development. The Verification phase (Phase 2) of DITSCAP C&A includes key activities such as certification analysis, assessment of analysis results, refining the SSAA configuration, and system development to integrate the system for testing.
Question
The Phase 2 of DITSCAP C&A is known as Verification. The goal of this phase is to obtain a fully integrated system for certification testing and accreditation. What are the process activities of this phase? Each correct answer represents a complete solution. Choose all that apply.
Options
- ACertification analysis
- BAssessment of the Analysis Results
- CConfiguring refinement of the SSAA
- DSystem development
- ERegistration
How the community answered
(53 responses)- A91% (48)
- E9% (5)
Why each option
The Verification phase (Phase 2) of DITSCAP C&A includes key activities such as certification analysis, assessment of analysis results, refining the SSAA configuration, and system development to integrate the system for testing.
Certification analysis is a key activity in the Verification phase, involving a detailed examination of the system's security controls and their implementation to determine compliance with security requirements.
Assessment of the Analysis Results involves reviewing the outcomes of the certification analysis to identify any gaps or non-compliance issues before proceeding to accreditation.
Configuring refinement of the System Security Accreditation Agreement (SSAA) involves updating and refining the security plan based on findings from the analysis and assessment, ensuring it accurately reflects the system's security posture.
System development, particularly in an iterative sense within the C&A lifecycle, can occur as part of this phase to implement or refine security controls identified during analysis and assessment, aiming for a fully integrated and secure system.
Registration is typically part of the initial or final steps (e.g., registering the system for accreditation or registering the accreditation status), but not a core 'process activity' within the Verification phase focused on building and testing the system.
Concept tested: DITSCAP C&A Verification phase activities
Topics
Community Discussion
No community discussion yet for this question.