nerdexam
(ISC)2

SSCP · Question #1217

In the DoD accreditation process a __________ is the formal entity which ensures that information systems meet a certain criteria for secure operation. Once approved these machines are certified to op

The correct answer is C. DAA - Designated Approving Authority. This question identifies the specific entity within the DoD accreditation process responsible for formally approving and certifying information systems for secure operation.

Submitted by akirajp· Apr 18, 2026Security Operations and Administration

Question

In the DoD accreditation process a __________ is the formal entity which ensures that information systems meet a certain criteria for secure operation. Once approved these machines are certified to operate with a set of listed safeguards.

Options

  • ADISA - Defense Information Systems Agency
  • BISC2 - International Information Systems Security Certification Consortium
  • CDAA - Designated Approving Authority
  • DISACA - The Information Systems Audit and Control Association

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    6% (3)
  • C
    87% (41)
  • D
    4% (2)

Why each option

This question identifies the specific entity within the DoD accreditation process responsible for formally approving and certifying information systems for secure operation.

ADISA - Defense Information Systems Agency

DISA (Defense Information Systems Agency) is a combat support agency providing IT and communications, but it is not the specific approving authority for system accreditation itself.

BISC2 - International Information Systems Security Certification Consortium

ISC2 (International Information Systems Security Certification Consortium) is a professional certification body, not a DoD accreditation authority.

CDAA - Designated Approving AuthorityCorrect

A Designated Approving Authority (DAA), now often referred to as an Authorizing Official (AO) under the Risk Management Framework, is the formal entity that assumes responsibility for the security posture of an information system and grants authorization for it to operate. This approval confirms the system meets specified security criteria and has appropriate safeguards.

DISACA - The Information Systems Audit and Control Association

ISACA (The Information Systems Audit and Control Association) is a global professional organization focused on IT governance, audit, and security, but not a DoD accreditation authority.

Concept tested: DoD system accreditation roles

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#DoD accreditation#DAA#Certification and Accreditation (C&A)#Risk Management Framework (RMF)

Community Discussion

No community discussion yet for this question.

Full SSCP Practice