Certification and Accreditation in Information Systems Security Engineering Professional Exam

Certification and Accreditation (C&A) Process

Question

Certification and Accreditation (C&A or CnA) is a process for implementing information security.

It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation.

Which of the following statements are true about Certification and Accreditation Each correct answer represents a complete solution.

Choose two.

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

CB.

Certification and Accreditation (C&A) is a security process for evaluating and authorizing information systems. The C&A process consists of two stages: Certification and Accreditation.

Certification is a technical evaluation of the security controls implemented in the information system. The goal of the certification process is to determine the effectiveness of security controls and identify vulnerabilities that need to be addressed. The certification process typically involves a thorough review of the system design, documentation, and testing of security controls to ensure they meet security requirements.

Accreditation is the formal management decision to authorize the operation of the information system based on the results of the certification process. The accreditation decision is made by a senior agency official who considers the results of the certification process along with other factors such as risk management, cost-benefit analysis, and legal compliance. Accreditation is the final step in the C&A process and indicates that the system has met all security requirements and is authorized to operate.

Therefore, options A and B are correct. Accreditation is a comprehensive assessment of the management, operational, and technical security controls in an information system, and it is the official management decision given by a senior agency official to authorize the operation of an information system.

Option C is incorrect because certification is not the official management decision to authorize operation of an information system. Certification is only a technical evaluation of the security controls in an information system.

Option D is incorrect because accreditation, not certification, is the official management decision given by a senior agency official to authorize operation of an information system.