CSSLP · Question #53
Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or…
The correct answer is A. Certification is a comprehensive assessment of the management, operational, and technical security C. Accreditation is the official management decision given by a senior agency official to authorize operation. Certification and Accreditation (C&A) is a two-part process for information security; certification is the comprehensive assessment, while accreditation is the formal management decision to authorize system operation.
Question
Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation? Each correct answer represents a complete solution. Choose two.
Options
- ACertification is a comprehensive assessment of the management, operational, and technical security
- BAccreditation is a comprehensive assessment of the management, operational, and technical security
- CAccreditation is the official management decision given by a senior agency official to authorize operation
- DCertification is the official management decision given by a senior agency official to authorize operation
How the community answered
(62 responses)- A89% (55)
- B8% (5)
- D3% (2)
Why each option
Certification and Accreditation (C&A) is a two-part process for information security; certification is the comprehensive assessment, while accreditation is the formal management decision to authorize system operation.
Certification involves a thorough technical and non-technical evaluation of a system's management, operational, and technical security posture against established requirements.
Accreditation is the official decision to authorize operation, not the comprehensive assessment of security.
Accreditation is the official management decision, typically by a senior agency official, to authorize the operation of an information system based on the results of the certification process and the residual risk.
Certification is the comprehensive security assessment, not the official management decision to authorize operation.
Concept tested: Certification and Accreditation (C&A) definitions
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-37.pdf
Topics
Community Discussion
No community discussion yet for this question.