QuestionQ243

Secure Software Lifecycle Management

Certification and Accreditation (C&A or CnA) is a process used to implement information security. Which of the following is the correct sequence of C&A phases in a DITSCAP assessment?

  • A Verification, Definition, Validation, and Post Accreditation
  • B Definition, Validation, Verification, and Post Accreditation
  • C Definition, Verification, Validation, and Post Accreditation
  • D Verification, Validation, Definition, and Post Accreditation
Explanation

DITSCAP proceeds through Definition, Verification, Validation, and Post Accreditation. Definition establishes the security requirements and accreditation effort; Verification assesses compliance during system development or modification; Validation assesses the fully integrated system; and Post Accreditation maintains the accepted security posture after accreditation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!