applying assessment authorization a a in the
Answers for CDSE's Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) course. Every answer is verified verbatim against the official CDSE student guide.
Studying for this with your unit? Send it to them.
01What are the prerequisites for starting the A&A process?
Before starting the A&A process, you should review your sponsorship documentation and security classification guidance, review the materials on the DCSA Risk Management Framework (RMF) website, and contact your local Information System Security Professional (ISSP) with any questions or concerns.
VERIFIED AGAINST THE SOURCE
βAs the Information System Security Manager, or ISSM, for a cleared contractor, there are several tasks you should perform before beginning the A&A process.β
β CDSE β Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β02What is the significance of the Risk Assessment Report (RAR) in the A&A process?
The RAR documents the results of the risk and threat assessment and influences the selection of security controls used to mitigate the risk associated with the Information System.
VERIFIED AGAINST THE SOURCE
βThe RAR documents the results of the risk and threat assessment.β
β CDSE β Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β03What are the three main outputs of the Categorize Step?
The three main outputs of the Categorize Step are a System Description, an updated NISP eMASS System Record, and the System Categorization.
VERIFIED AGAINST THE SOURCE
βCategorize Step results in the creation of three main items: a System Description, an updated NISP eMASS System Record, and the System Categorization.β
β CDSE β Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β04What is the role of the Information Owner (IO) during the Categorize Step?
The IO is the authority for determining categorization and must be involved in the process of categorizing the data and system.
VERIFIED AGAINST THE SOURCE
βThe categorization of the data and system must be coordinated with the IO.β
β CDSE β Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β05What types of security controls are defined in the Select Step?
The types of security controls defined in the Select Step are system-specific, common, and hybrid controls.
VERIFIED AGAINST THE SOURCE
βThere are three types of security controls: system specific, common, and hybrid.β
β CDSE β Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β06What is the purpose of continuous monitoring in the Select Step?
Continuous monitoring is used to determine whether the planned security control implementation is acceptable and includes configuration management and control, security impact analyses on proposed changes, assessment of selected security controls, and security status reporting.
VERIFIED AGAINST THE SOURCE
βContinuous monitoring is a critical part of risk management and is used to determine whether the planned security control implementation is acceptable.β
β CDSE β Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β07What is the final task of the System Level Prepare Step?
The final task is registering the system in the NISP eMASS instance.
VERIFIED AGAINST THE SOURCE
βThis was the final system level task.β
β CDSE β Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β08What is the DCSA baseline categorization for Information Systems seeking authorization?
The DCSA baseline categorization is a Moderate impact due to loss of confidentiality and a Low impact due to loss of integrity or availability.
VERIFIED AGAINST THE SOURCE
βThe DCSA baseline categorization is a Moderate impact due to loss of confidentiality and a Low impact due to loss of integrity or availability.β
β CDSE β Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β09What is the role of the ISSM in the Implement Step?
The ISSM implements the security controls identified in the Security Control Selection and documents the implementation while looking for any weaknesses.
VERIFIED AGAINST THE SOURCE
βIn this step, the ISSM implements the security controls identified in the Security Control Selection.β
β CDSE β Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β10What is the purpose of tailoring security controls in the Select Step?
Tailoring security controls allows the ISSM to supplement the baseline with additional controls or to remove controls that do not apply or are satisfied by mitigating factors, providing justification in the security plan.
VERIFIED AGAINST THE SOURCE
βIn Task S-2, the ISSM tailors the baseline security controls as needed.β
β CDSE β Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide β11What is the significance of the NISP eMASS in the A&A process?
NISP eMASS is the government-owned, web-based application that manages the A&A process and is used to populate information and upload artifacts, including generating a Security Plan.
VERIFIED AGAINST THE SOURCE
βNISP eMASS is the portal to manage the A&A process.β
β CDSE β Applying Assessment & Authorization (A&A) in the National Industrial Security Program (NISP) (CS250.16) Student Guide βKnow questions we're missing?
Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.
Study these as flashcards
Load all 11 questions into a free study set β flashcards, a practice test, and spaced repetition. No account.
Works on any PDF, doc or web page too β not just military training.
Veteran? vetaid.ai β free VA benefits help.