ExamGecko
Question list
Search
Search

Question 425 - CISM discussion

Report
Export

Which of the following BEST minimizes information security risk in deploying applications to the production environment?

A.
Integrating security controls in each phase of the life cycle
Answers
A.
Integrating security controls in each phase of the life cycle
B.
Conducting penetration testing post implementation
Answers
B.
Conducting penetration testing post implementation
C.
Having a well-defined change process
Answers
C.
Having a well-defined change process
D.
Verifying security during the testing process
Answers
D.
Verifying security during the testing process
Suggested answer: A

Explanation:

= Integrating security controls in each phase of the life cycle is the best way to minimize information security risk in deploying applications to the production environment. This ensures that security requirements are defined, designed, implemented, tested, and maintained throughout the development process. Conducting penetration testing post implementation, having a well-defined change process, and verifying security during the testing process are all important activities, but they are not sufficient to address all the potential risks that may arise during the application life cycle. Penetration testing may reveal some vulnerabilities, but it cannot guarantee that all of them are identified and fixed. A change process may help to control and document the modifications made to the application, but it does not ensure that the changes are secure and do not introduce new risks.Verifying security during the testing process may help to validate the functionality and performance of the security controls, but it does not ensure that the security requirements are complete and consistent with the business objectives and the risk appetite of the organization.Reference= CISM Review Manual, 16th Edition, page 1121; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 1462

asked 01/10/2024
IOSSIF ZINGUER
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first