ExamGecko
Question list
Search
Search

Question 421 - CISM discussion

Report
Export

To improve the efficiency of the development of a new software application, security requirements should be defined:

A.
based on code review.
Answers
A.
based on code review.
B.
based on available security assessment tools.
Answers
B.
based on available security assessment tools.
C.
after functional requirements.
Answers
C.
after functional requirements.
D.
concurrently with other requirements.
Answers
D.
concurrently with other requirements.
Suggested answer: D

Explanation:

Security requirements should be defined concurrently with other requirements to ensure that security is built into the software development process from the beginning and not added as an afterthought. This will also improve the efficiency of the development process by reducing the need for rework and testing.Security requirements should be based on the business objectives, risk assessment, and security policies of the organization, not on code review, security assessment tools, or functional requirements.Reference= CISM Review Manual 15th Edition, page 1241; CISM Item Development Guide, page 62

asked 01/10/2024
Felomino Bacquiano II
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first