New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CSSLP Exam - Topic 8 Question 19 Discussion

Actual exam question for ISC2's CSSLP exam
Question #: 19
Topic #: 8
[All CSSLP Questions]

Certification and Accreditation (C&A or CnA) is a process for implementing information security. Which of the following is the correct order of C&A phases in a DITSCAP assessment?

Show Suggested Answer Hide Answer
Suggested Answer: C

C&A consists of four phases in a DITSCAP assessment. These phases are the same as NIACAP phases. The order of these phases is as

follows:

1.Definition: The definition phase is focused on understanding the IS business case, the mission, environment, and architecture. This

phase determines the security requirements and level of effort necessary to achieve Certification & Accreditation (C&A).

2.Verification: The second phase confirms the evolving or modified system's compliance with the information. The verification phase

ensures that the fully integrated system will be ready for certification testing.

3.Validation: The third phase confirms abidance of the fully integrated system with the security policy. This phase follows the

requirements slated in the SSAA. The objective of the validation phase is to show the required evidence to support the DAA in

accreditation process.

4.Post Accreditation: The Post Accreditation is the final phase of DITSCAP assessment and it starts after the system has been certified

and accredited for operations. This phase ensures secure system management, operation, and maintenance to save an acceptable

level of residual risk.


Contribute your Thoughts:

0/2000 characters
Fredric
4 months ago
Just to clarify, it's not A or D, right?
upvoted 0 times
...
Blondell
4 months ago
Wait, are we sure about this? Sounds confusing.
upvoted 0 times
...
Gladys
4 months ago
Totally agree with C! That's the right order.
upvoted 0 times
...
Crista
4 months ago
I thought it was Verification first? Seems off.
upvoted 0 times
...
Stephane
5 months ago
It's definitely Definition, Validation, Verification, and Post Accreditation!
upvoted 0 times
...
Brock
5 months ago
I keep mixing up Verification and Validation; I hope I picked the right one for this question.
upvoted 0 times
...
Caprice
5 months ago
I remember practicing a question like this, and I think it was C: Definition, Verification, Validation, and Post Accreditation.
upvoted 0 times
...
Amie
5 months ago
I think the order starts with Definition, but I'm not sure if it's A or B after that.
upvoted 0 times
...
Annice
5 months ago
I thought the phases were in a different order, but I can't recall the exact sequence. Maybe it's B?
upvoted 0 times
...
Louvenia
5 months ago
No problem, I've got a strategy. I'll use the MAX() function and make sure to reference the "Total Sales" column. Should be easy to knock out.
upvoted 0 times
...
Bernardine
5 months ago
Okay, I've got this. The WBS process outputs the project scope statement, accepted deliverables, and the scope baseline. I'll select the option that matches that.
upvoted 0 times
...

Save Cancel