QuestionQ239

Secure Software Lifecycle Management

Which phase of the NIST SP 800-37 C&A methodology evaluates residual risk for acceptability and prepares the final security accreditation package?

  • A Security Accreditation
  • B Initiation
  • C Continuous Monitoring
  • D Security Certification
Explanation

The Security Accreditation phase determines whether the residual risk is acceptable to the authorizing official and concludes with the final security accreditation documentation/package, including the accreditation decision letter.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!