QuestionQ21

Secure Software Lifecycle Management

Which of the following processes ends with an agreement among key players that a system, in its current configuration and operation, provides adequate protection controls?

  • A Information Assurance (IA)
  • B Information systems security engineering (ISSE)
  • C Certification and accreditation (C&A)
  • D Risk Management
Explanation

Certification and accreditation (C&A) assesses the system’s management, operational, and technical security controls and supports the formal authorization decision to operate based on an agreed-upon set of controls and accepted risk.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!