nerdexam
(ISC)2

CSSLP · Question #350

Which of the following are the phases of the Certification and Accreditation (C&A) process? Each correct answer represents a complete solution. Choose two.

The correct answer is A. Continuous Monitoring D. Initiation. The Certification and Accreditation (C&A) process, now largely superseded by the Risk Management Framework (RMF), traditionally included phases like Initiation and Continuous Monitoring. Initiation begins the C&A process, while Continuous Monitoring ensures ongoing security…

Secure Software Lifecycle Management

Question

Which of the following are the phases of the Certification and Accreditation (C&A) process? Each correct answer represents a complete solution. Choose two.

Options

  • AContinuous Monitoring
  • BAuditing
  • CDetection
  • DInitiation

How the community answered

(32 responses)
  • A
    91% (29)
  • B
    3% (1)
  • C
    6% (2)

Why each option

The Certification and Accreditation (C&A) process, now largely superseded by the Risk Management Framework (RMF), traditionally included phases like Initiation and Continuous Monitoring. Initiation begins the C&A process, while Continuous Monitoring ensures ongoing security posture and compliance.

AContinuous MonitoringCorrect

Continuous Monitoring is a critical phase in modern C&A (now RMF) processes, involving ongoing assessment and monitoring of security controls to maintain an acceptable security posture and react to changes.

BAuditing

Auditing is an activity that occurs within different phases of C&A/RMF (e.g., during assessment or continuous monitoring), but it is not a standalone phase of the C&A process itself.

CDetection

Detection is a function of security controls (e.g., IDS/IPS) to identify security events, not a distinct phase of the C&A process.

DInitiationCorrect

Initiation is the first phase of the C&A process where the system is defined, its boundaries are established, and the necessary resources for the C&A effort are allocated.

Concept tested: Certification and Accreditation (C&A) Phases

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Certification and Accreditation (C&A)#Risk Management Framework (RMF)#Security Authorization Process#Information System Security

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice