nerdexam
(ISC)2

CISSP · Question #108

During the procurement of a new information system, it was determined that some of the security requirements were not addressed in the system specification. Which of the following is the MOST likely r

The correct answer is D. The description of the security requirements was insufficient.. When security requirements are not addressed in a system specification during procurement, the most likely root cause is that the requirements themselves were not clearly or completely documented in the first place.

Submitted by yaw92· Mar 5, 2026Security and Risk Management

Question

During the procurement of a new information system, it was determined that some of the security requirements were not addressed in the system specification. Which of the following is the MOST likely reason for this?

Options

  • AThe procurement officer lacks technical knowledge.
  • BThe security requirements have changed during the procurement process.
  • CThere were no security professionals in the vendor's bidding team.
  • DThe description of the security requirements was insufficient.

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    16% (5)
  • C
    26% (8)
  • D
    52% (16)

Why each option

When security requirements are not addressed in a system specification during procurement, the most likely root cause is that the requirements themselves were not clearly or completely documented in the first place.

AThe procurement officer lacks technical knowledge.

The procurement officer's technical knowledge level does not directly cause security requirements to be absent from the system specification, as procurement officers rely on documented requirements provided by stakeholders rather than generating technical security requirements themselves.

BThe security requirements have changed during the procurement process.

While changing requirements can cause misalignment, this is a less likely and less common root cause than insufficient initial documentation, and the question asks for the MOST likely reason.

CThere were no security professionals in the vendor's bidding team.

The vendor's bidding team composition is irrelevant to whether security requirements are captured in the system specification, since vendors respond to requirements they are given rather than defining the buyer's security needs.

DThe description of the security requirements was insufficient.Correct

If security requirements are insufficiently described - lacking specificity, measurability, or completeness - vendors cannot accurately interpret or implement them in the system specification. This is a fundamental principle in systems engineering and secure acquisition: requirements must be clearly articulated before they can be addressed. Vague or incomplete requirements documentation is the most direct and common reason for gaps between intended security controls and delivered system specifications.

Concept tested: Security requirements documentation in system procurement

Source: https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final

Topics

#security requirements#system procurement#requirements definition#risk management

Community Discussion

No community discussion yet for this question.

Full CISSP Practice