CSSLP · Question #315
Which of the following phases of NIST SP 800-37 C&A methodology examines the residual risk for acceptability, and prepares the final security accreditation package?
The correct answer is A. Security Accreditation. The Security Accreditation phase of NIST SP 800-37 involves a designated official reviewing the system's security posture, determining the acceptability of residual risk, and formally authorizing the system to operate.
Question
Which of the following phases of NIST SP 800-37 C&A methodology examines the residual risk for acceptability, and prepares the final security accreditation package?
Options
- ASecurity Accreditation
- BInitiation
- CContinuous Monitoring
- DSecurity Certification
How the community answered
(58 responses)- A95% (55)
- B3% (2)
- C2% (1)
Why each option
The Security Accreditation phase of NIST SP 800-37 involves a designated official reviewing the system's security posture, determining the acceptability of residual risk, and formally authorizing the system to operate.
The Security Accreditation phase is where a senior agency official reviews the security plan, certification results, and risk determinations to make a decision on whether to authorize the system to operate, considering the residual risk and preparing the final accreditation package.
Initiation is the first phase, focusing on defining the system boundary and identifying responsible parties, not risk acceptability or final package preparation.
Continuous Monitoring occurs after accreditation, regularly assessing security controls to ensure they remain effective over time.
Security Certification involves testing and evaluating the security controls to determine if they are implemented correctly and effectively, providing a technical assessment, but it does not make the final risk acceptability decision or prepare the final accreditation package.
Concept tested: NIST RMF (C&A) phases - Accreditation
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev2/final
Topics
Community Discussion
No community discussion yet for this question.