CAS-001 · Question #121
A team of security engineers has applied regulatory and corporate guidance to the design of a corporate network. The engineers have generated an SRTM based on their work and a thorough analysis of…
The correct answer is D. To allow certifiers to verify the network meets applicable security requirements. A Security Requirements Traceability Matrix (SRTM) is a document that maps every security requirement - drawn from regulatory mandates, corporate policy, and functional/performance specifications - to the specific design controls, implementation artifacts, or test cases that…
Question
A team of security engineers has applied regulatory and corporate guidance to the design of a corporate network. The engineers have generated an SRTM based on their work and a thorough analysis of the complete set of functional and performance requirements in the network specification. Which of the following BEST describes the purpose of an SRTM in this scenario?
Options
- ATo ensure the security of the network is documented prior to customer delivery
- BTo document the source of all functional requirements applicable to the network
- CTo facilitate the creation of performance testing metrics and test plans
- DTo allow certifiers to verify the network meets applicable security requirements
How the community answered
(43 responses)- A16% (7)
- B9% (4)
- C5% (2)
- D70% (30)
Explanation
A Security Requirements Traceability Matrix (SRTM) is a document that maps every security requirement - drawn from regulatory mandates, corporate policy, and functional/performance specifications - to the specific design controls, implementation artifacts, or test cases that satisfy it. Its core purpose is auditability and verification: it gives certifiers, auditors, and accreditation authorities a structured way to confirm that every applicable security requirement has been addressed in the final design. Option A is partially true but describes documentation as a delivery artifact rather than the matrix's function. Option B describes only one input (source of requirements), not the purpose of the full traceability chain. Option C conflates performance testing metrics with security traceability - those are separate activities. Option D correctly identifies that the SRTM exists so that an independent party (certifier) can trace requirements through to their implementation and verify compliance.
Topics
Community Discussion
No community discussion yet for this question.