List of questions
Related questions
Question 1082 - CISSP discussion
A healthcare insurance organization chose a vendor to develop a software application. Upon review of the draft contract, the information security professional notices that software security is not addressed. What is the BEST approach to address the issue?
A.
Update the service level agreement (SLA) to provide the organization the right to audit the vendor.
B.
Update the service level agreement (SLA) to require the vendor to provide security capabilities.
C.
Update the contract so that the vendor is obligated to provide security capabilities.
D.
Update the contract to require the vendor to perform security code reviews.
Your answer:
0 comments
Sorted by
Leave a comment first