CSSLP · Question #54
The Phase 1 of DITSCAP C&A is known as Definition Phase. The goal of this phase is to define the C&A level of effort, identify the main C&A roles and responsibilities, and create an agreement on the m
The correct answer is A. Negotiation B. Registration C. Document mission need. The Definition Phase (Phase 1) of DITSCAP C&A involves initial setup activities, including negotiation, system registration, and documenting the mission need.
Question
The Phase 1 of DITSCAP C&A is known as Definition Phase. The goal of this phase is to define the C&A level of effort, identify the main C&A roles and responsibilities, and create an agreement on the method for implementing the security requirements. What are the process activities of this phase? Each correct answer represents a complete solution. Choose all that apply.
Options
- ANegotiation
- BRegistration
- CDocument mission need
- DInitial Certification Analysis
How the community answered
(70 responses)- A91% (64)
- D9% (6)
Why each option
The Definition Phase (Phase 1) of DITSCAP C&A involves initial setup activities, including negotiation, system registration, and documenting the mission need.
Negotiation occurs in Phase 1 to agree on the C&A level of effort, security requirements, and the approach for implementation.
Registration involves formally registering the information system within the organization's C&A process, which is part of establishing the C&A effort.
Documenting mission need is crucial in Phase 1 to understand the system's purpose and operational environment, which helps define the scope of the C&A.
Initial Certification Analysis is typically part of the Certification Phase (Phase 2), where the actual security assessment and analysis begin, not the initial definition phase.
Concept tested: DITSCAP C&A Definition Phase activities
Source: null
Topics
Community Discussion
No community discussion yet for this question.