CISSP · Question #96
What is the FIRST step in developing a security test and its evaluation?
The correct answer is C. Identify all applicable security requirements. Developing a security test begins with identifying all applicable security requirements, as you cannot design or evaluate a test without first knowing what standards and controls must be met.
Question
Options
- ADetermine testing methods
- BDevelop testing procedures
- CIdentify all applicable security requirements
- DIdentify people, processes, and products not in compliance
How the community answered
(43 responses)- A7% (3)
- B14% (6)
- C74% (32)
- D5% (2)
Why each option
Developing a security test begins with identifying all applicable security requirements, as you cannot design or evaluate a test without first knowing what standards and controls must be met.
Determining testing methods comes after requirements are identified, since the chosen methods must align with and be driven by the specific security requirements that apply.
Developing testing procedures is a later step that translates requirements and selected methods into actionable steps, and cannot be done meaningfully before requirements are established.
Identifying all applicable security requirements is the foundational first step because it establishes the scope and baseline criteria against which all testing will be measured. Without knowing which regulatory, organizational, or technical security requirements apply, there is no basis for determining what to test, how to test it, or what constitutes a pass or fail. All subsequent steps - such as selecting methods and developing procedures - depend on this requirements baseline.
Identifying people, processes, and products not in compliance is an outcome or result of executing the security test, not a step in initially developing the test itself.
Concept tested: Security test development lifecycle and planning sequence
Source: https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.