ExamGecko
Question list
Search
Search

Question 349 - CISM discussion

Report
Export

Which of the following is the BEST option to lower the cost to implement application security controls?

A.
Perform security tests in the development environment.
Answers
A.
Perform security tests in the development environment.
B.
Integrate security activities within the development process
Answers
B.
Integrate security activities within the development process
C.
Perform a risk analysis after project completion.
Answers
C.
Perform a risk analysis after project completion.
D.
Include standard application security requirements
Answers
D.
Include standard application security requirements
Suggested answer: B

Explanation:

Integrating security activities within the development process is the best option to lower the cost to implement application security controls because it ensures that security is considered and addressed throughout the software development life cycle (SDLC), from design to deployment, and reduces the likelihood and impact of security flaws or vulnerabilities that may require costly fixes or patches later on. Performing security tests in the development environment is not the best option because it may not detect or prevent all security issues that may arise in different environments or scenarios. Performing a risk analysis after project completion is not a good option because it may be too late to identify or mitigate security risks that may have been introduced during the project. Including standard application security requirements is not a good option because it may not account for specific or unique security needs or challenges of different applications or projects.

Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/secure-software-development-lifecycle https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information-systems

asked 01/10/2024
Brooke Galiata
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first