nerdexam
CompTIA

CAS-001 · Question #292

The risk committee has endorsed the adoption of a security system development life cycle (SSDLC) designed to ensure compliance with PCI-DSS, HIPAA, and meet the organization's mission. Which of the…

The correct answer is B. Initiation, acquisition/development, implementation/assessment, operations/maintenance and sunset. The standard five-phase SDLC/SSDLC order, as defined by NIST SP 800-64 and widely referenced in security frameworks, is: (1) Initiation - define purpose, scope, and security requirements; (2) Acquisition/Development - design, procure, or build the system with security built in…

Integration of Computing, Communications and Business Disciplines

Question

The risk committee has endorsed the adoption of a security system development life cycle (SSDLC) designed to ensure compliance with PCI-DSS, HIPAA, and meet the organization's mission. Which of the following BEST describes the correct order of implementing a five phase SSDLC?

Options

  • AInitiation, assessment/acquisition, development/implementation, operations/maintenance and sunset.
  • BInitiation, acquisition/development, implementation/assessment, operations/maintenance and sunset.
  • CAssessment, initiation/development, implementation/assessment, operations/maintenance and disposal.
  • DAcquisition, initiation/development, implementation/assessment, operations/maintenance and disposal.

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    95% (38)
  • D
    3% (1)

Explanation

The standard five-phase SDLC/SSDLC order, as defined by NIST SP 800-64 and widely referenced in security frameworks, is: (1) Initiation - define purpose, scope, and security requirements; (2) Acquisition/Development - design, procure, or build the system with security built in; (3) Implementation/Assessment - deploy and formally test/certify security controls; (4) Operations/Maintenance - run the system and apply ongoing patches and monitoring; (5) Sunset/Disposal - securely decommission and sanitize data. Option B matches this sequence exactly. Options A, C, and D either misordering the phases or conflate steps that belong in distinct phases (e.g., placing 'assessment' before development or combining 'initiation' with 'development').

Topics

#SSDLC#software development lifecycle#PCI-DSS#HIPAA compliance

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice