nerdexam
CompTIA

CAS-002 · Question #127

The risk committee has endorsed the adoption of a security system development life cycle (SSDLC) designed to ensure compliance with PCI-DSS, HIPAA, and meet the organization's mission. Which of the…

The correct answer is B. Initiation, acquisition/development, implementation/assessment, operations/maintenance. The correct five-phase SSDLC order follows the NIST SP 800-64 framework: Initiation, Acquisition/Development, Implementation/Assessment, Operations/Maintenance, and Disposal.

Enterprise Security

Question

The risk committee has endorsed the adoption of a security system development life cycle (SSDLC) designed to ensure compliance with PCI-DSS, HIPAA, and meet the organization's mission. Which of the following BEST describes the correct order of implementing a five phase SSDLC?

Options

  • AInitiation, assessment/acquisition, development/implementation, operations/maintenance
  • BInitiation, acquisition/development, implementation/assessment, operations/maintenance
  • CAssessment, initiation/development, implementation/assessment, operations/maintenance
  • DAcquisition, initiation/development, implementation/assessment, operations/maintenance

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    95% (36)
  • C
    3% (1)

Why each option

The correct five-phase SSDLC order follows the NIST SP 800-64 framework: Initiation, Acquisition/Development, Implementation/Assessment, Operations/Maintenance, and Disposal.

AInitiation, assessment/acquisition, development/implementation, operations/maintenance

Placing 'assessment/acquisition' before 'development/implementation' inverts the correct NIST SSDLC order, as acquisition and development must occur before implementation and assessment can be conducted.

BInitiation, acquisition/development, implementation/assessment, operations/maintenanceCorrect

NIST SP 800-64 defines the security-focused system development life cycle with phases ordered as Initiation, Development/Acquisition, Implementation/Assessment, Operations/Maintenance, and Disposal - answer B correctly places Initiation first and follows the logical progression from planning through development, security testing, and sustained operations, which aligns with the standard NIST model.

CAssessment, initiation/development, implementation/assessment, operations/maintenance

Beginning with 'Assessment' before 'Initiation' is incorrect because a meaningful security or risk assessment cannot be performed before the system concept, scope, and objectives have been formally defined in the initiation phase.

DAcquisition, initiation/development, implementation/assessment, operations/maintenance

Starting with 'Acquisition' before 'Initiation' skips the planning and scoping phase that must precede any procurement or development activity in the NIST SSDLC framework.

Concept tested: NIST SSDLC five-phase correct implementation order

Source: https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/final

Topics

#SSDLC phases#PCI-DSS#HIPAA#security lifecycle

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice