Security accreditation is the formal authorization by the accrediting (management) official for system operation and an explicit acceptance of risk. It is usually supported by a review of the system, including its management, operational, and technical controls.
A system certification is conducted first and system accreditation is next because the former supports the latter. Security certification and security accreditation processes follow the system certification and system accreditation processes.
70. Which of the following is a nonresident virus?
a.
Master boot sector virusb.
File infector virusc.
Macro virusd.
Boot-sector infector71. Backdoors are which of the following?
a.
They are entry points into a computer program.b.
They are choke points into a computer program.c.
They are halt points into a computer program.d.
They are exit points into a computer program.72. Most Trojan horses can be prevented and detected by which of the following?
a.
Removing the damageb.
Assessing the damagec.
Installing program change controlsd.
Correcting the damage73. From a risk analysis viewpoint, what does the major vulnerable area in a computer application system include?
a.
Internal computer processingb.
System inputs and outputsc.
Telecommunications and networksd.
External computer processing74. Which of the following is
a.
Configuration fileb.
Password filec.
Log filed.
System file75. Which of the following software assurance processes is responsible for ensuring that any changes to software outputs during the system development process are made in a controlled and complete manner?
a.
Software configuration management processesb.
Software project management processesc.
Software quality assurance processesd.
Software verification and validation processesThe objective of the project management process is to establish the organizational structure of the project and assign responsibilities. This process uses the system requirements documentation and information about the purpose of the software, criticality of the software, required deliverables, and available time and resources to plan and manage the software development and software assurance processes. It establishes or approves standards, monitoring and reporting practices, and high-level policy for quality, and it cites policies and regulations.