nerdexam
Isaca

CISM · Question #680

An organization is planning to engage a third-party service provider to develop custom software. Which of the following would help to provide the GREATEST assurance of software security?

The correct answer is D. Independent assessment against a relevant standard. An independent assessment against a relevant standard provides the greatest assurance of software security by objectively verifying that secure development practices are being followed and controls are effectively implemented.

Submitted by saadiq_pk· Apr 18, 2026Information Security Risk Management

Question

An organization is planning to engage a third-party service provider to develop custom software. Which of the following would help to provide the GREATEST assurance of software security?

Options

  • ASecurity training for the service provider's software development staff
  • BReview of the service provider's software development policies
  • CVerification of certifications held by the individual developers
  • DIndependent assessment against a relevant standard

How the community answered

(23 responses)
  • A
    9% (2)
  • B
    13% (3)
  • C
    22% (5)
  • D
    57% (13)

Explanation

An independent assessment against a relevant standard provides the greatest assurance of software security by objectively verifying that secure development practices are being followed and controls are effectively implemented.

Topics

#Third-party risk management#Software security assurance#Vendor security assessment#Risk mitigation

Community Discussion

No community discussion yet for this question.

Full CISM Practice