nerdexam
CompTIA

CAS-001 · Question #212

SDLC is being used for the commissioning of a new platform. To provide an appropriate level of assurance the security requirements that were specified at the project origin need to be carried…

The correct answer is C. Security requirements traceability matrix (SRTM). A Security Requirements Traceability Matrix (SRTM) is specifically designed to track each security requirement from its origin through design, development, testing, and implementation. It creates a visible, auditable linkage that proves every requirement was addressed at every…

Integration of Computing, Communications and Business Disciplines

Question

SDLC is being used for the commissioning of a new platform. To provide an appropriate level of assurance the security requirements that were specified at the project origin need to be carried through to implementation. Which of the following would BEST help to determine if this occurred?

Options

  • ARequirements workshop
  • BSecurity development lifecycle (SDL)
  • CSecurity requirements traceability matrix (SRTM)
  • DSecure code review and penetration test

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    89% (34)
  • D
    3% (1)

Explanation

A Security Requirements Traceability Matrix (SRTM) is specifically designed to track each security requirement from its origin through design, development, testing, and implementation. It creates a visible, auditable linkage that proves every requirement was addressed at every phase. A requirements workshop (A) is useful for gathering requirements, not verifying they were carried through. SDL (B) is a process framework, not a verification artifact. Secure code review and penetration testing (D) can reveal gaps but do not systematically trace requirements back to their origin the way an SRTM does.

Topics

#SRTM#security requirements traceability#SDLC#requirements validation

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice