Which of the following SDLC phases consists of the given security controls: Misuse Case Modeling
Security Design and Architecture Review
Threat and Risk Modeling
Security Requirements and Test Cases Generation
The DAA, also known as Authorizing Official, makes the final accreditation decision. The Designated Approving Authority (DAA), in the United
States Department of Defense, is the official with the authority to formally assume responsibility for operating a system at an acceptable level
of risk. The DAA is responsible for implementing system security. The DAA can grant the accreditation and can determine that the system's
risks are not at an acceptable level and the system is not ready to be operational.
Answer D is incorrect. An Information System Security Officer (ISSO) plays the role of a supporter. The responsibilities of an Information
System Security Officer (ISSO) are as follows:
Manages the security of the information system that is slated for Certification & Accreditation (C&A).
Insures the information systems configuration with the agency's information security policy.
Supports the information system owner/information owner for the completion of security-related responsibilities.
Takes part in the formal configuration management process.
Prepares Certification & Accreditation (C&A) packages.
Answer A is incorrect. An Information System Security Engineer (ISSE) plays the role of an advisor. The responsibilities of an
Information System Security Engineer are as follows:
Provides view on the continuous monitoring of the information system.
Provides advice on the impacts of system changes.
Takes part in the configuration management process.
Takes part in the development activities that are required to implement system changes.
Follows approved system changes.
Answer B is incorrect. A Chief Risk Officer (CRO) is also known as Chief Risk Management Officer (CRMO). The Chief Risk Officer or Chief
Risk Management Officer of a corporation is the executive accountable for enabling the efficient and effective governance of significant risks,
and related opportunities, to a business and its various segments. Risks are commonly categorized as strategic, reputational, operational,
financial, or compliance-related. CRO's are accountable to the Executive Committee and The Board for enabling the business to balance risk
and reward. In more complex organizations, they are generally responsible for coordinating the organization's Enterprise Risk Management
(ERM) approach.
Mitzie
3 months agoLenora
3 months agoPhil
3 months agoMaynard
4 months agoFrancine
4 months agoJohana
4 months agoLachelle
4 months agoLigia
4 months agoBeatriz
5 months agoYasuko
5 months agoLawanda
5 months agoJade
5 months agoAllene
5 months agoFelix
5 months agoPortia
5 months agoWai
5 months agoTresa
5 months agoMauricio
9 months agoMelinda
9 months agoKassandra
8 months agoWilliam
8 months agoJarvis
8 months agoLizbeth
9 months agoRonald
10 months agoTran
10 months agoAlaine
8 months agoArmando
8 months agoBrynn
9 months agoFausto
10 months agoReynalda
9 months agoNakisha
9 months agoEladia
11 months agoLindsay
11 months agoLonny
11 months ago