<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need Assistance in Understanding Difference Between Certification And Assurance in Exam Preparation</title>
    <link>https://community.isc2.org/t5/Exam-Preparation/Need-Assistance-in-Understanding-Difference-Between/m-p/39834#M3253</link>
    <description>&amp;gt; mitewarrior (Viewer) posted a new topic in Exam Preparation on 10-08-2020 02:13&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I just&lt;BR /&gt;&amp;gt; wanted to understand on the difference between Certification and Accreditation.&lt;BR /&gt;&lt;BR /&gt;Certification (of a system, not a security professional) is the process of testing&lt;BR /&gt;and assessment to ensure that the system does what it is supposed to do, and will&lt;BR /&gt;have the impact on security, and provide the protection, that the&lt;BR /&gt;client/customer/system owner expects. (Certification may be part of the&lt;BR /&gt;assurance requirements for security overall, and may be based on the functional&lt;BR /&gt;requirements.)&lt;BR /&gt;&lt;BR /&gt;Accreditation is the formal acceptance, by senior management or the system&lt;BR /&gt;owner, of the system. In a perfect world, one would expect accreditation to rely&lt;BR /&gt;on certification. However, there are cases where senior management may accredit&lt;BR /&gt;a system where certification has taken place, or refuse to accredit a system that&lt;BR /&gt;has passed certification.&lt;BR /&gt;&lt;BR /&gt;======================&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;"If you do buy a computer, don't turn it on." - Richards' 2nd Law&lt;BR /&gt;"Robert Slade's Guide to Computer Viruses" 0-387-94663-2&lt;BR /&gt;"Viruses Revealed" 0-07-213090-3&lt;BR /&gt;"Software Forensics" 0-07-142804-6&lt;BR /&gt;"Dictionary of Information Security" Syngress 1-59749-115-2&lt;BR /&gt;"Cybersecurity Lessons from CoVID-19" CRC Press 0367682699&lt;BR /&gt;============= for back issues:&lt;BR /&gt;[Base URL] site &lt;A href="http://victoria.tc.ca/techrev/" target="_blank"&gt;http://victoria.tc.ca/techrev/&lt;/A&gt;&lt;BR /&gt;CISSP refs: [Base URL]mnbksccd.htm&lt;BR /&gt;PC Security: [Base URL]mnvrrvsc.htm&lt;BR /&gt;Security Dict.: [Base URL]secgloss.htm&lt;BR /&gt;Security Educ.: [Base URL]comseced.htm&lt;BR /&gt;Book reviews: [Base URL]mnbk.htm&lt;BR /&gt;[Base URL]review.htm&lt;BR /&gt;Partial/recent: &lt;A href="http://groups.yahoo.com/group/techbooks/" target="_blank"&gt;http://groups.yahoo.com/group/techbooks/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://en.wikipedia.org/wiki/Robert_Slade" target="_blank"&gt;http://en.wikipedia.org/wiki/Robert_Slade&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt; &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;</description>
    <pubDate>Thu, 08 Oct 2020 18:37:01 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2020-10-08T18:37:01Z</dc:date>
    <item>
      <title>Need Assistance in Understanding Difference Between Certification And Assurance</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Need-Assistance-in-Understanding-Difference-Between/m-p/39833#M3252</link>
      <description>&lt;P&gt;Am really sorry if this post is not at all related to this forum as i have recently joined so am not sure exactly on the terms. But i just wanted to ask a question to be clarified regarding my CISSP exam preperation.&lt;BR /&gt;I just wanted to understand on the difference between Certification and Accreditation. If a person "A" designing and evaluating a system in a environment does not report correctly and the same report goes to the management for accreditation review and for some unfortunate reasons the system fails so the onus would be on the management who had signed it or on the person "A" who had missed to report the details evaluated correctly.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 18:13:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Need-Assistance-in-Understanding-Difference-Between/m-p/39833#M3252</guid>
      <dc:creator>mitewarrior</dc:creator>
      <dc:date>2020-10-08T18:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Need Assistance in Understanding Difference Between Certification And Assurance</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Need-Assistance-in-Understanding-Difference-Between/m-p/39834#M3253</link>
      <description>&amp;gt; mitewarrior (Viewer) posted a new topic in Exam Preparation on 10-08-2020 02:13&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I just&lt;BR /&gt;&amp;gt; wanted to understand on the difference between Certification and Accreditation.&lt;BR /&gt;&lt;BR /&gt;Certification (of a system, not a security professional) is the process of testing&lt;BR /&gt;and assessment to ensure that the system does what it is supposed to do, and will&lt;BR /&gt;have the impact on security, and provide the protection, that the&lt;BR /&gt;client/customer/system owner expects. (Certification may be part of the&lt;BR /&gt;assurance requirements for security overall, and may be based on the functional&lt;BR /&gt;requirements.)&lt;BR /&gt;&lt;BR /&gt;Accreditation is the formal acceptance, by senior management or the system&lt;BR /&gt;owner, of the system. In a perfect world, one would expect accreditation to rely&lt;BR /&gt;on certification. However, there are cases where senior management may accredit&lt;BR /&gt;a system where certification has taken place, or refuse to accredit a system that&lt;BR /&gt;has passed certification.&lt;BR /&gt;&lt;BR /&gt;======================&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;"If you do buy a computer, don't turn it on." - Richards' 2nd Law&lt;BR /&gt;"Robert Slade's Guide to Computer Viruses" 0-387-94663-2&lt;BR /&gt;"Viruses Revealed" 0-07-213090-3&lt;BR /&gt;"Software Forensics" 0-07-142804-6&lt;BR /&gt;"Dictionary of Information Security" Syngress 1-59749-115-2&lt;BR /&gt;"Cybersecurity Lessons from CoVID-19" CRC Press 0367682699&lt;BR /&gt;============= for back issues:&lt;BR /&gt;[Base URL] site &lt;A href="http://victoria.tc.ca/techrev/" target="_blank"&gt;http://victoria.tc.ca/techrev/&lt;/A&gt;&lt;BR /&gt;CISSP refs: [Base URL]mnbksccd.htm&lt;BR /&gt;PC Security: [Base URL]mnvrrvsc.htm&lt;BR /&gt;Security Dict.: [Base URL]secgloss.htm&lt;BR /&gt;Security Educ.: [Base URL]comseced.htm&lt;BR /&gt;Book reviews: [Base URL]mnbk.htm&lt;BR /&gt;[Base URL]review.htm&lt;BR /&gt;Partial/recent: &lt;A href="http://groups.yahoo.com/group/techbooks/" target="_blank"&gt;http://groups.yahoo.com/group/techbooks/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://en.wikipedia.org/wiki/Robert_Slade" target="_blank"&gt;http://en.wikipedia.org/wiki/Robert_Slade&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt; &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;</description>
      <pubDate>Thu, 08 Oct 2020 18:37:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Need-Assistance-in-Understanding-Difference-Between/m-p/39834#M3253</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-10-08T18:37:01Z</dc:date>
    </item>
  </channel>
</rss>

