CISSP · Question #616
Which of the following steps should be conducted during the FIRST phase of software assurance in a generic acquisition process?
The correct answer is C. Developing software requirements to be included in work statement. In a generic software acquisition process, the first phase involves defining what you need before any procurement activities begin. Developing software requirements is the foundational step that precedes all other acquisition activities.
Question
Options
- AEstablishing and consenting to the contract work schedule
- BIssuing a Request for proposal (RFP) with a work statement
- CDeveloping software requirements to be included in work statement
- DReviewing and accepting software deliverables
How the community answered
(34 responses)- A9% (3)
- B6% (2)
- C82% (28)
- D3% (1)
Why each option
In a generic software acquisition process, the first phase involves defining what you need before any procurement activities begin. Developing software requirements is the foundational step that precedes all other acquisition activities.
Establishing and consenting to the contract work schedule occurs in a later phase, after requirements have been defined, an RFP issued, and a contractor selected - it is part of contract negotiation and award, not the initial phase.
Issuing a Request for Proposal (RFP) with a work statement is a mid-process step that can only occur after requirements have been developed and incorporated into the work statement, making it a second or third phase activity.
Developing software requirements to be included in the work statement is the first phase because you must define and document what the software must do before you can communicate needs to vendors or issue any procurement documents. These requirements form the technical and functional basis for the work statement, which is then used in subsequent phases like the RFP. Without established requirements, no meaningful acquisition activity can proceed.
Reviewing and accepting software deliverables is a final-phase activity that occurs after development is complete and the software is delivered, representing the end of the acquisition lifecycle, not the beginning.
Concept tested: Software assurance phases in acquisition process
Source: https://www.cisa.gov/sites/default/files/publications/infosheet_SoftwareAssurance_Feb2010.pdf
Topics
Community Discussion
No community discussion yet for this question.