nerdexam
(ISC)2

CISSP · Question #1339

An organization plans to acquire @ commercial off-the-shelf (COTS) system to replace their aging home-built reporting system. When should the organization's security team FIRST get involved in this…

The correct answer is A. When the system is being designed, purchased, programmed, developed, or otherwise. The security team should be involved in the acquisition life cycle as early as possible, preferably when the need for a system is expressed and the purpose of the system is documented. This will ensure that the security requirements are identified and incorporated into the…

Submitted by anjalisingh· Mar 5, 2026Software Development Security

Question

An organization plans to acquire @ commercial off-the-shelf (COTS) system to replace their aging home-built reporting system. When should the organization's security team FIRST get involved in this acquisition's life cycle?

Options

  • AWhen the system is being designed, purchased, programmed, developed, or otherwise
  • BWhen the system is verified and validated
  • CWhen the system is deployed into production
  • DWhen the need for a system is expressed and the purpose of the system Is documented

How the community answered

(24 responses)
  • A
    71% (17)
  • B
    8% (2)
  • C
    17% (4)
  • D
    4% (1)

Explanation

The security team should be involved in the acquisition life cycle as early as possible, preferably when the need for a system is expressed and the purpose of the system is documented. This will ensure that the security requirements are identified and incorporated into the system design, purchase, development, and testing phases. Waiting until the system is verified and validated or deployed into production may be too late to address any security issues or risks that could have been prevented or mitigated earlier.

Topics

#COTS acquisition#SDLC#security by design#early security involvement

Community Discussion

No community discussion yet for this question.

Full CISSP Practice