Network Security Certification and Accreditation:
Do you think a formal process like Certification & Accreditation is appropriate to use for commercial systems in private industry? Discuss why/why not and suggest the important parts of C&A to carry over to the commercial sector. Alternatively, if you have worked in industry describe briefly any security review process used in your company before putting a system into use, and discuss the pros and cons of this in contrast to Department of Defense Information Assurance Certification and Accreditation Process (DIACAP). (Aside-at least some large companies that I have worked with have something similar, but not as formal, usually related to, or as part of "acceptance testing.")