Certification and Accreditation
Certification and accreditation is sometimes referred to as "Security Authorization."
4 slides · 2 min read · Domain 8
Certification is defined as the formal process of evaluating the security capabilities of the software or system against a predetermined set of security standards or policies. Certification can also examine how well the system performs its intended functional requirements related to security.
In other words, certification is the comprehensive technical security analysis of the system to ensure that it meets all applicable security requirements; accreditation is the formal management decision regarding the results of certification, which is sometimes used as the authorization to move the system into operational (or production) use.
Usually, this requires a designated accrediting authority (DAA) to review and approve. Some government systems environments and their customer agencies) have strict requirements for certification and accreditation, and the authorization to operate that flows from those processes. Most commercial organizations do not see the benefits to be gained from the administrative burdens of such formalized processes.
The result of this certification process should contain an analysis of the technical and nontechnical security capabilities and countermeasures and the extent to which the software or system meets the security requirements.
Once the software has been certified to meet the requirements, management needs to review the certification and authorize the system to be implemented in production for a specific period of time. This is the process referred to as accreditation.
There are two types of accreditation, provisional and full:
- Provisional accreditation is for a specific period and, therefore, outlines required changes to the applications, system, or accreditation to meet full accreditation requirements and status.
- Full accreditation implies that no changes are required for making the accreditation decision.
Note that management and owners may choose to accredit a system that has failed certification or may refuse to accredit a system even if it has been certified as meeting the requirements.
To ensure proper and valuable testing, the application should be tested in an environment that simulates as much as possible, the actual production environment.
This should include testing the security capabilities and simulating other security-related problems that may arise. This is the first phase of what is commonly referred to as the certification and accreditation process.
