CGEIT · Question #290
Following the rollout of an enterprise IT software solution that hosts sensitive data it was discovered that the application's role-based access control was not functioning as specified. Which of the
The correct answer is B. Ensure the evaluation process requires independent assessment of solutions prior to. The failure of a critical security feature like RBAC indicates insufficient verification before deployment; independent assessment before rollout is the best preventative measure.
Question
Following the rollout of an enterprise IT software solution that hosts sensitive data it was discovered that the application's role-based access control was not functioning as specified. Which of the following is the BEST way to prevent reoccurrence in the future?
Options
- AEnsure supplier contracts include penalties if solutions do not meet functional requirements
- BEnsure the evaluation process requires independent assessment of solutions prior to
- CEnsure supplier contracts include a provision for the right to audit on an annual basis
- DEnsure procurement processes require the identification of alternate vendors to ensure business
How the community answered
(24 responses)- A4% (1)
- B83% (20)
- C8% (2)
- D4% (1)
Why each option
The failure of a critical security feature like RBAC indicates insufficient verification before deployment; independent assessment before rollout is the best preventative measure.
Penalties are reactive measures for non-compliance and do not prevent issues from occurring in the first place.
An independent assessment of solutions prior to rollout, particularly for critical functions like role-based access control (RBAC) handling sensitive data, provides an objective verification that the solution meets all specified functional and security requirements. This proactive testing by a party separate from the development or integration team can identify and remediate defects before they impact production, preventing reoccurrence of such issues after deployment.
An annual audit is a periodic review; the issue occurred upon rollout, suggesting a need for upfront verification rather than post-deployment auditing.
Identifying alternate vendors is a procurement strategy for business continuity and competition, not a direct measure to prevent functionality errors in a deployed solution.
Concept tested: Software quality assurance, pre-deployment testing
Source: https://learn.microsoft.com/en-us/azure/security/develop/secure-development-lifecycle
Topics
Community Discussion
No community discussion yet for this question.