nerdexam
(ISC)2

CISSP · Question #1506

An organization purchased a commercial off-the-shelf (COTS) software several years ago. The information technology (IT) Director has decided to migrate the application into the cloud, but is concerned

The correct answer is D. Examine the software updating and patching process. The software updating and patching process is a critical factor for ensuring the security of a commercial off-the-shelf (COTS) software, especially when it is migrated to the cloud. The organization should examine how the software vendor provides updates and patches, how frequent

Submitted by mateo_ar· Mar 5, 2026Software Development Security

Question

An organization purchased a commercial off-the-shelf (COTS) software several years ago. The information technology (IT) Director has decided to migrate the application into the cloud, but is concerned about the application security of the software in the organization's dedicated environment with a cloud service provider. What is the BEST way to prevent and correct the software's security weaknesses?

Options

  • AImplement a dedicated COTS sandbox environment
  • BFollow the software end-of-life schedule
  • CTransfer the risk to the cloud service provider
  • DExamine the software updating and patching process

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    18% (5)
  • C
    7% (2)
  • D
    71% (20)

Explanation

The software updating and patching process is a critical factor for ensuring the security of a commercial off-the-shelf (COTS) software, especially when it is migrated to the cloud. The organization should examine how the software vendor provides updates and patches, how frequently they are released, how they are tested and verified, and how they are applied to the software in the cloud environment. The organization should also monitor the software end-of-life schedule and plan for migration or replacement when necessary.

Topics

#COTS security#application security#patch management#vulnerability management

Community Discussion

No community discussion yet for this question.

Full CISSP Practice