CISSP · Question #108
During the procurement of a new information system, it was determined that some of the security requirements were not addressed in the system specification. Which of the following is the MOST likely r
The correct answer is D. The description of the security requirements was insufficient.. When security requirements are not addressed in a system specification during procurement, the most likely root cause is that the requirements themselves were not clearly or completely documented in the first place.
Question
Options
- AThe procurement officer lacks technical knowledge.
- BThe security requirements have changed during the procurement process.
- CThere were no security professionals in the vendor's bidding team.
- DThe description of the security requirements was insufficient.
How the community answered
(31 responses)- A6% (2)
- B16% (5)
- C26% (8)
- D52% (16)
Why each option
When security requirements are not addressed in a system specification during procurement, the most likely root cause is that the requirements themselves were not clearly or completely documented in the first place.
The procurement officer's technical knowledge level does not directly cause security requirements to be absent from the system specification, as procurement officers rely on documented requirements provided by stakeholders rather than generating technical security requirements themselves.
While changing requirements can cause misalignment, this is a less likely and less common root cause than insufficient initial documentation, and the question asks for the MOST likely reason.
The vendor's bidding team composition is irrelevant to whether security requirements are captured in the system specification, since vendors respond to requirements they are given rather than defining the buyer's security needs.
If security requirements are insufficiently described - lacking specificity, measurability, or completeness - vendors cannot accurately interpret or implement them in the system specification. This is a fundamental principle in systems engineering and secure acquisition: requirements must be clearly articulated before they can be addressed. Vague or incomplete requirements documentation is the most direct and common reason for gaps between intended security controls and delivered system specifications.
Concept tested: Security requirements documentation in system procurement
Source: https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final
Topics
Community Discussion
No community discussion yet for this question.