CAS-003 · Question #711
A government entity is developing requirements for an RFP to acquire a biometric authentication system. When developing these requirements, which of the following considerations is MOST critical to…
The correct answer is A. Local and national laws and regulations. A Security Requirements Traceability Matrix (SRTM) maps security requirements to their source artifacts to verify and validate that every requirement is addressed. For a government biometric authentication system, local and national laws and regulations (e.g., biometric data…
Question
A government entity is developing requirements for an RFP to acquire a biometric authentication system. When developing these requirements, which of the following considerations is MOST critical to the verification and validation of the SRTM?
Options
- ALocal and national laws and regulations
- BSecure software development requirements
- CEnvironmental constraint requirements
- DTestability of requirements
How the community answered
(33 responses)- A55% (18)
- B6% (2)
- C24% (8)
- D15% (5)
Explanation
A Security Requirements Traceability Matrix (SRTM) maps security requirements to their source artifacts to verify and validate that every requirement is addressed. For a government biometric authentication system, local and national laws and regulations (e.g., biometric data privacy laws, identity management statutes, or sector-specific mandates) are the foundational source from which requirements must be derived and traced. Without legal compliance as the baseline, the entire SRTM lacks legitimacy. Secure software development (B), environmental constraints (C), and testability (D) are important but are downstream considerations - the legal and regulatory framework is the most critical anchor for SRTM verification and validation in a government procurement context.
Topics
Community Discussion
No community discussion yet for this question.