Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 Exam ISSEP Topic 4 Question 20 Discussion

Actual exam question for ISC2's Information Systems Security Engineering Professional exam
Question #: 20
Topic #: 4
[All Information Systems Security Engineering Professional Questions]

Which of the following DITSCAP/NIACAP model phases is used to show the required evidence to

support the DAA in accreditation process and conclude in an Approval To Operate (ATO)?

Show Suggested Answer Hide Answer
Suggested Answer: B

he DAA in accreditation process and conclude in an Approval To Operate (ATO).

C&A consists of four phases in a DITSCAP assessment. These phases are the same as NIACAP phases.

The order of these phases is as

follows:

1.Definition: The definition phase is focused on understanding the IS business case, the mission,

environment, and architecture. This

phase determines the security requirements and level of effort necessary to achieve Certification &

Accreditation (C&A).

2.Verification: The second phase confirms the evolving or modified system's compliance with the

information. The verification phase

ensures that the fully integrated system will be ready for certification testing.

3.Validation: The third phase confirms abidance of the fully integrated system with the security

policy. This phase follows the

requirements slated in the SSAA. The objective of the validation phase is to show the required

evidence to support the DAA in

accreditation process.

4.Post Accreditation: The Post Accreditation is the final phase of DITSCAP assessment and it starts

after the system has been certified

and accredited for operations. This phase ensures secure system management, operation, and

maintenance to save an acceptable

level of residual risk.


Contribute your Thoughts:

Currently there are no comments in this discussion, be the first to comment!


Save Cancel