nerdexam
(ISC)2

CSSLP · Question #53

Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or…

The correct answer is A. Certification is a comprehensive assessment of the management, operational, and technical security C. Accreditation is the official management decision given by a senior agency official to authorize operation. Certification and Accreditation (C&A) is a two-part process for information security; certification is the comprehensive assessment, while accreditation is the formal management decision to authorize system operation.

Secure Software Deployment, Operations, Maintenance

Question

Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation? Each correct answer represents a complete solution. Choose two.

Options

  • ACertification is a comprehensive assessment of the management, operational, and technical security
  • BAccreditation is a comprehensive assessment of the management, operational, and technical security
  • CAccreditation is the official management decision given by a senior agency official to authorize operation
  • DCertification is the official management decision given by a senior agency official to authorize operation

How the community answered

(62 responses)
  • A
    89% (55)
  • B
    8% (5)
  • D
    3% (2)

Why each option

Certification and Accreditation (C&A) is a two-part process for information security; certification is the comprehensive assessment, while accreditation is the formal management decision to authorize system operation.

ACertification is a comprehensive assessment of the management, operational, and technical securityCorrect

Certification involves a thorough technical and non-technical evaluation of a system's management, operational, and technical security posture against established requirements.

BAccreditation is a comprehensive assessment of the management, operational, and technical security

Accreditation is the official decision to authorize operation, not the comprehensive assessment of security.

CAccreditation is the official management decision given by a senior agency official to authorize operationCorrect

Accreditation is the official management decision, typically by a senior agency official, to authorize the operation of an information system based on the results of the certification process and the residual risk.

DCertification is the official management decision given by a senior agency official to authorize operation

Certification is the comprehensive security assessment, not the official management decision to authorize operation.

Concept tested: Certification and Accreditation (C&A) definitions

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-37.pdf

Topics

#Certification and Accreditation (C&A)#Certification#Accreditation#System Authorization

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice