nerdexam
(ISC)2

CSSLP · Question #346

Who amongst the following makes the final accreditation decision?

The correct answer is C. DAA. The Designated Approving Authority (DAA) is the individual responsible for making the final decision to authorize or accredit an information system for operation. This decision signifies that the system's security posture is acceptable and that it can operate within its specified

Secure Software Deployment, Operations, Maintenance

Question

Who amongst the following makes the final accreditation decision?

Options

  • AISSE
  • BCRO
  • CDAA
  • DISSO

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    85% (28)
  • D
    3% (1)

Why each option

The Designated Approving Authority (DAA) is the individual responsible for making the final decision to authorize or accredit an information system for operation. This decision signifies that the system's security posture is acceptable and that it can operate within its specified environment.

AISSE

An Information System Security Engineer (ISSE) designs, develops, and implements security solutions for information systems, but does not make accreditation decisions.

BCRO

A Chief Risk Officer (CRO) is typically responsible for overseeing an organization's overall risk management strategy, but the DAA holds the specific authority for system accreditation decisions.

CDAACorrect

The Designated Approving Authority (DAA) is the senior management official who formally accepts the risk of operating an information system and makes the final decision on whether to accredit it for production use. The DAA weighs the security posture against mission requirements and organizational risk tolerance.

DISSO

An Information System Security Officer (ISSO) is responsible for the day-to-day security posture and operations of an information system, working under the DAA's guidance but not making the final accreditation decision.

Concept tested: Certification and Accreditation (C&A) Roles - DAA

Source: https://csrc.nist.gov/glossary/term/authorizing_official

Topics

#Accreditation#Authorization#DAA#Risk Management

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice