nerdexam
(ISC)2

CSSLP · Question #54

The Phase 1 of DITSCAP C&A is known as Definition Phase. The goal of this phase is to define the C&A level of effort, identify the main C&A roles and responsibilities, and create an agreement on the m

The correct answer is A. Negotiation B. Registration C. Document mission need. The Definition Phase (Phase 1) of DITSCAP C&A involves initial setup activities, including negotiation, system registration, and documenting the mission need.

Secure Software Deployment, Operations, Maintenance

Question

The Phase 1 of DITSCAP C&A is known as Definition Phase. The goal of this phase is to define the C&A level of effort, identify the main C&A roles and responsibilities, and create an agreement on the method for implementing the security requirements. What are the process activities of this phase? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ANegotiation
  • BRegistration
  • CDocument mission need
  • DInitial Certification Analysis

How the community answered

(70 responses)
  • A
    91% (64)
  • D
    9% (6)

Why each option

The Definition Phase (Phase 1) of DITSCAP C&A involves initial setup activities, including negotiation, system registration, and documenting the mission need.

ANegotiationCorrect

Negotiation occurs in Phase 1 to agree on the C&A level of effort, security requirements, and the approach for implementation.

BRegistrationCorrect

Registration involves formally registering the information system within the organization's C&A process, which is part of establishing the C&A effort.

CDocument mission needCorrect

Documenting mission need is crucial in Phase 1 to understand the system's purpose and operational environment, which helps define the scope of the C&A.

DInitial Certification Analysis

Initial Certification Analysis is typically part of the Certification Phase (Phase 2), where the actual security assessment and analysis begin, not the initial definition phase.

Concept tested: DITSCAP C&A Definition Phase activities

Source: null

Topics

#DITSCAP#Certification & Accreditation#Security Frameworks#Definition Phase

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice