CSSLP · Question #350
Which of the following are the phases of the Certification and Accreditation (C&A) process? Each correct answer represents a complete solution. Choose two.
The correct answer is A. Continuous Monitoring D. Initiation. The Certification and Accreditation (C&A) process, now largely superseded by the Risk Management Framework (RMF), traditionally included phases like Initiation and Continuous Monitoring. Initiation begins the C&A process, while Continuous Monitoring ensures ongoing security…
Question
Which of the following are the phases of the Certification and Accreditation (C&A) process? Each correct answer represents a complete solution. Choose two.
Options
- AContinuous Monitoring
- BAuditing
- CDetection
- DInitiation
How the community answered
(32 responses)- A91% (29)
- B3% (1)
- C6% (2)
Why each option
The Certification and Accreditation (C&A) process, now largely superseded by the Risk Management Framework (RMF), traditionally included phases like Initiation and Continuous Monitoring. Initiation begins the C&A process, while Continuous Monitoring ensures ongoing security posture and compliance.
Continuous Monitoring is a critical phase in modern C&A (now RMF) processes, involving ongoing assessment and monitoring of security controls to maintain an acceptable security posture and react to changes.
Auditing is an activity that occurs within different phases of C&A/RMF (e.g., during assessment or continuous monitoring), but it is not a standalone phase of the C&A process itself.
Detection is a function of security controls (e.g., IDS/IPS) to identify security events, not a distinct phase of the C&A process.
Initiation is the first phase of the C&A process where the system is defined, its boundaries are established, and the necessary resources for the C&A effort are allocated.
Concept tested: Certification and Accreditation (C&A) Phases
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.