CAS-001 · Question #212
SDLC is being used for the commissioning of a new platform. To provide an appropriate level of assurance the security requirements that were specified at the project origin need to be carried…
The correct answer is C. Security requirements traceability matrix (SRTM). A Security Requirements Traceability Matrix (SRTM) is specifically designed to track each security requirement from its origin through design, development, testing, and implementation. It creates a visible, auditable linkage that proves every requirement was addressed at every…
Question
SDLC is being used for the commissioning of a new platform. To provide an appropriate level of assurance the security requirements that were specified at the project origin need to be carried through to implementation. Which of the following would BEST help to determine if this occurred?
Options
- ARequirements workshop
- BSecurity development lifecycle (SDL)
- CSecurity requirements traceability matrix (SRTM)
- DSecure code review and penetration test
How the community answered
(38 responses)- A3% (1)
- B5% (2)
- C89% (34)
- D3% (1)
Explanation
A Security Requirements Traceability Matrix (SRTM) is specifically designed to track each security requirement from its origin through design, development, testing, and implementation. It creates a visible, auditable linkage that proves every requirement was addressed at every phase. A requirements workshop (A) is useful for gathering requirements, not verifying they were carried through. SDL (B) is a process framework, not a verification artifact. Secure code review and penetration testing (D) can reveal gaps but do not systematically trace requirements back to their origin the way an SRTM does.
Topics
Community Discussion
No community discussion yet for this question.