CAP Exam: DITSCAP C&A Phases and System Accreditation

DITSCAP C&A Phases: SSAA Signing to System Accreditation

Question

Which of the following DITSCAP C&A phases takes place between the signing of the initial version of the SSAA and the formal accreditation of the system?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

C.

DITSCAP (Department of Defense Information Technology Security Certification and Accreditation Process) is a process used to ensure that the information systems meet security requirements. The process consists of six phases:

  1. Definition of the system and security requirements
  2. Development of the system security architecture
  3. Analysis of the security requirements
  4. Implementation and testing of the security controls
  5. Formal security certification
  6. Accreditation of the system for operation

The System Security Authorization Agreement (SSAA) is a key document in the DITSCAP process, which outlines the security requirements for the system, and is signed by the authorizing official.

Based on the provided question, the phase that takes place between the signing of the initial version of the SSAA and the formal accreditation of the system is:

Answer: D. Phase 4

Phase 4, Implementation and testing of the security controls, takes place after the signing of the initial version of the SSAA and before the formal accreditation of the system. This phase involves implementing and testing the security controls outlined in the SSAA, as well as assessing the effectiveness of the controls in meeting the security requirements.

Therefore, the correct answer is D. Phase 4.