ExamGecko
Home Home / ISC / CISSP
Question list
Search
Search

Question 1082 - CISSP discussion

Report
Export

A healthcare insurance organization chose a vendor to develop a software application. Upon review of the draft contract, the information security professional notices that software security is not addressed. What is the BEST approach to address the issue?

A.
Update the service level agreement (SLA) to provide the organization the right to audit the vendor.
Answers
A.
Update the service level agreement (SLA) to provide the organization the right to audit the vendor.
B.
Update the service level agreement (SLA) to require the vendor to provide security capabilities.
Answers
B.
Update the service level agreement (SLA) to require the vendor to provide security capabilities.
C.
Update the contract so that the vendor is obligated to provide security capabilities.
Answers
C.
Update the contract so that the vendor is obligated to provide security capabilities.
D.
Update the contract to require the vendor to perform security code reviews.
Answers
D.
Update the contract to require the vendor to perform security code reviews.
Suggested answer: C
asked 18/09/2024
Ilya Shadrin
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first