CISSP · Question #1509
Which of the following is the GREATEST risk of relying only on Capability Maturity Models (CMM) for software to guide process improvement and assess capabilities of acquired software?
The correct answer is B. CMMs do not explicitly address safety and security. The greatest risk of relying only on Capability Maturity Models (CMMs) for software to guide process improvement and assess capabilities of acquired software is that CMMs do not explicitly address safety and security. CMMs are frameworks that measure and improve the maturity and
Question
Which of the following is the GREATEST risk of relying only on Capability Maturity Models (CMM) for software to guide process improvement and assess capabilities of acquired software?
Options
- AOrganizations can only reach a maturity level 3 when using CMMs
- BCMMs do not explicitly address safety and security
- CCMMs can only be used for software developed in-house
- DCMMs are vendor specific and may be biased
How the community answered
(28 responses)- A4% (1)
- B79% (22)
- C14% (4)
- D4% (1)
Explanation
The greatest risk of relying only on Capability Maturity Models (CMMs) for software to guide process improvement and assess capabilities of acquired software is that CMMs do not explicitly address safety and security. CMMs are frameworks that measure and improve the maturity and quality of the software development processes and products. CMMs define different levels of maturity, from initial to optimized, based on the presence and effectiveness of the key process areas, such as requirements management, project planning, configuration management, quality assurance, or risk management. CMMs can help to evaluate and improve the software development processes and products, but they do not explicitly address the safety and security aspects of the software. Safety and security are important attributes of the software, especially for critical or sensitive applications, such as medical, military, or financial applications. Safety and security require specific processes and practices, such as threat modeling, secure coding, vulnerability testing, or incident response, that are not covered by the CMMs. Therefore, relying only on CMMs for software may result in overlooking or neglecting the safety and security issues of the software, which may lead to serious consequences, such as harm, loss, or breach. Organizations can only reach a maturity level 3 when using CMMs, CMMs can only be used for software developed in-house, and CMMs are vendor specific and may be biased are not the greatest risks of relying only on CMMs for software. These are some of the limitations or challenges of using CMMs for software, but they are not as significant or critical as the lack of safety and security. Organizations can reach higher maturity levels than level 3 when using CMMs, depending on the implementation and assessment of the CMMs. CMMs can be used for software developed in-house or outsourced, depending on the scope and criteria of the CMMs. CMMs are not vendor specific and may not be biased, as they are based on industry standards and best practices, such as ISO/IEC 15504 or ISO/IEC 33001.
Topics
Community Discussion
No community discussion yet for this question.