← Back to CBT Library

applying assessment authorization a a in the

Answers for CDSE's Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) course. Every answer is verified verbatim against the official CDSE student guide.

11 questions and answers11 of 11 verified against the official source

Studying for this with your unit? Send it to them.

πŸƒ Flashcards
01What are the prerequisites for starting the A&A process?
A:

Before starting the A&A process, you should review your sponsorship documentation and security classification guidance, review the materials on the DCSA Risk Management Framework (RMF) website, and contact your local Information System Security Professional (ISSP) with any questions or concerns.

VERIFIED AGAINST THE SOURCE

β€œAs the Information System Security Manager, or ISSM, for a cleared contractor, there are several tasks you should perform before beginning the A&A process.”

β€” CDSE β€” Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β†—
02What is the significance of the Risk Assessment Report (RAR) in the A&A process?
A:

The RAR documents the results of the risk and threat assessment and influences the selection of security controls used to mitigate the risk associated with the Information System.

VERIFIED AGAINST THE SOURCE

β€œThe RAR documents the results of the risk and threat assessment.”

β€” CDSE β€” Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β†—
03What are the three main outputs of the Categorize Step?
A:

The three main outputs of the Categorize Step are a System Description, an updated NISP eMASS System Record, and the System Categorization.

VERIFIED AGAINST THE SOURCE

β€œCategorize Step results in the creation of three main items: a System Description, an updated NISP eMASS System Record, and the System Categorization.”

β€” CDSE β€” Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β†—
04What is the role of the Information Owner (IO) during the Categorize Step?
A:

The IO is the authority for determining categorization and must be involved in the process of categorizing the data and system.

VERIFIED AGAINST THE SOURCE

β€œThe categorization of the data and system must be coordinated with the IO.”

β€” CDSE β€” Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β†—
05What types of security controls are defined in the Select Step?
A:

The types of security controls defined in the Select Step are system-specific, common, and hybrid controls.

VERIFIED AGAINST THE SOURCE

β€œThere are three types of security controls: system specific, common, and hybrid.”

β€” CDSE β€” Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β†—
06What is the purpose of continuous monitoring in the Select Step?
A:

Continuous monitoring is used to determine whether the planned security control implementation is acceptable and includes configuration management and control, security impact analyses on proposed changes, assessment of selected security controls, and security status reporting.

VERIFIED AGAINST THE SOURCE

β€œContinuous monitoring is a critical part of risk management and is used to determine whether the planned security control implementation is acceptable.”

β€” CDSE β€” Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β†—
07What is the final task of the System Level Prepare Step?
A:

The final task is registering the system in the NISP eMASS instance.

08What is the DCSA baseline categorization for Information Systems seeking authorization?
A:

The DCSA baseline categorization is a Moderate impact due to loss of confidentiality and a Low impact due to loss of integrity or availability.

VERIFIED AGAINST THE SOURCE

β€œThe DCSA baseline categorization is a Moderate impact due to loss of confidentiality and a Low impact due to loss of integrity or availability.”

β€” CDSE β€” Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β†—
09What is the role of the ISSM in the Implement Step?
A:

The ISSM implements the security controls identified in the Security Control Selection and documents the implementation while looking for any weaknesses.

VERIFIED AGAINST THE SOURCE

β€œIn this step, the ISSM implements the security controls identified in the Security Control Selection.”

β€” CDSE β€” Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β†—
10What is the purpose of tailoring security controls in the Select Step?
A:

Tailoring security controls allows the ISSM to supplement the baseline with additional controls or to remove controls that do not apply or are satisfied by mitigating factors, providing justification in the security plan.

VERIFIED AGAINST THE SOURCE

β€œIn Task S-2, the ISSM tailors the baseline security controls as needed.”

β€” CDSE β€” Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β†—
11What is the significance of the NISP eMASS in the A&A process?
A:

NISP eMASS is the government-owned, web-based application that manages the A&A process and is used to populate information and upload artifacts, including generating a Security Plan.

Know questions we're missing?

Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.

Study these as flashcards

Load all 11 questions into a free study set β€” flashcards, a practice test, and spaced repetition. No account.

Works on any PDF, doc or web page too β€” not just military training.

Veteran? vetaid.ai β€” free VA benefits help.