CISSP Practice Question (Domain 8: Software Development Security)
A development team adopts a widely used open source library that accelerates delivery of a revenue-critical release. The library has no active maintainer and no published vulnerability disclosure process. What should the security manager recommend FIRST?
A. Add the library to the software bill of materials for monitoring
B. Evaluate the component against secure acquisition and supply chain criteria
C. Fork the library so the organization controls future patching
D. Require compensating controls at the application perimeter
(Explain your answer for more points in the comments!)
Come back for the answer tomorrow, or study more now!
0
11 comments
Vincent Primiani
7
CISSP Practice Question (Domain 8: Software Development Security)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by