CAS-002 · Question #127
The risk committee has endorsed the adoption of a security system development life cycle (SSDLC) designed to ensure compliance with PCI-DSS, HIPAA, and meet the organization's mission. Which of the…
The correct answer is B. Initiation, acquisition/development, implementation/assessment, operations/maintenance. The correct five-phase SSDLC order follows the NIST SP 800-64 framework: Initiation, Acquisition/Development, Implementation/Assessment, Operations/Maintenance, and Disposal.
Question
The risk committee has endorsed the adoption of a security system development life cycle (SSDLC) designed to ensure compliance with PCI-DSS, HIPAA, and meet the organization's mission. Which of the following BEST describes the correct order of implementing a five phase SSDLC?
Options
- AInitiation, assessment/acquisition, development/implementation, operations/maintenance
- BInitiation, acquisition/development, implementation/assessment, operations/maintenance
- CAssessment, initiation/development, implementation/assessment, operations/maintenance
- DAcquisition, initiation/development, implementation/assessment, operations/maintenance
How the community answered
(38 responses)- A3% (1)
- B95% (36)
- C3% (1)
Why each option
The correct five-phase SSDLC order follows the NIST SP 800-64 framework: Initiation, Acquisition/Development, Implementation/Assessment, Operations/Maintenance, and Disposal.
Placing 'assessment/acquisition' before 'development/implementation' inverts the correct NIST SSDLC order, as acquisition and development must occur before implementation and assessment can be conducted.
NIST SP 800-64 defines the security-focused system development life cycle with phases ordered as Initiation, Development/Acquisition, Implementation/Assessment, Operations/Maintenance, and Disposal - answer B correctly places Initiation first and follows the logical progression from planning through development, security testing, and sustained operations, which aligns with the standard NIST model.
Beginning with 'Assessment' before 'Initiation' is incorrect because a meaningful security or risk assessment cannot be performed before the system concept, scope, and objectives have been formally defined in the initiation phase.
Starting with 'Acquisition' before 'Initiation' skips the planning and scoping phase that must precede any procurement or development activity in the NIST SSDLC framework.
Concept tested: NIST SSDLC five-phase correct implementation order
Source: https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.