ExamGecko
Question list
Search
Search

Question 161 - CISM discussion

Report
Export

Which of the following would BEST help to ensure appropriate security controls are built into software?

A.
Integrating security throughout the development process
Answers
A.
Integrating security throughout the development process
B.
Performing security testing prior to deployment
Answers
B.
Performing security testing prior to deployment
C.
Providing standards for implementation during development activities
Answers
C.
Providing standards for implementation during development activities
D.
Providing security training to the software development team
Answers
D.
Providing security training to the software development team
Suggested answer: A

Explanation:

The best way to ensure appropriate security controls are built into software is to integrate security throughout the development process. This means that security should be considered from the initial stages of planning, design, coding, testing, deployment, and maintenance of the software. Integrating security throughout the development process helps to identify and mitigate security risks early, reduce the cost and complexity of fixing vulnerabilities later, improve the quality and reliability of the software, and enhance the trust and confidence of the users and customers.Integrating security throughout the development process also aligns with the best practices and standards of information security governance, such as the CISM framework123.

Reference=

CISM Review Manual 15th Edition, page 1631

CISM domain 3: Information security program development and management [2022 update]2

CISSP domain 8 overview: Software development security4

asked 01/10/2024
Kristian Gutierrez
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first