QuestionQ309

Secure Software Lifecycle Management

Continuous Monitoring is the fourth phase of the security certification and accreditation process. Which activities are carried out during the Continuous Monitoring process? Each correct answer represents a complete solution. Choose all that apply.

Choose three
  • A Security accreditation decision
  • B Security control monitoring and impact analyses of changes to the information system
  • C Security accreditation documentation
  • D Configuration management and control
  • E Status reporting and documentation
Explanation

Continuous monitoring maintains the security posture of an accredited information system through configuration management and control, ongoing monitoring of security controls and analysis of system changes, and status reporting with supporting documentation. Accreditation decisions and accreditation documentation are activities of the security accreditation phase.

Community Discussion

No comments yet. Be the first to start the discussion!