nerdexam
(ISC)2

CSSLP · Question #227

In which of the following SDLC phases is the system's security features configured and enabled, the system is tested and installed or fielded, and the system is authorized for processing?

The correct answer is C. Implementation Phase. The Implementation Phase of the SDLC is where a system's security features are configured and activated, the system undergoes testing, is installed, and receives authorization to operate. This phase transitions the system from development to a functional, secure state.

Secure Software Deployment, Operations, Maintenance

Question

In which of the following SDLC phases is the system's security features configured and enabled, the system is tested and installed or fielded, and the system is authorized for processing?

Options

  • ADevelopment/Acquisition Phase
  • BOperation/Maintenance Phase
  • CImplementation Phase
  • DInitiation Phase

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    88% (23)

Why each option

The Implementation Phase of the SDLC is where a system's security features are configured and activated, the system undergoes testing, is installed, and receives authorization to operate. This phase transitions the system from development to a functional, secure state.

ADevelopment/Acquisition Phase

The Development/Acquisition Phase focuses on designing, coding, and acquiring the system, not typically the final configuration, testing, and authorization for processing.

BOperation/Maintenance Phase

The Operation/Maintenance Phase focuses on the day-to-day operation, monitoring, and ongoing maintenance of the system after it has been deployed, not the initial configuration, testing, and installation.

CImplementation PhaseCorrect

The Implementation Phase of the System Development Life Cycle (SDLC) is specifically where the system is built, integrated, tested, and installed in its operational environment. During this phase, security features are configured and enabled, the system undergoes comprehensive security testing (e.g., vulnerability scanning, penetration testing), and finally, it is installed or "fielded" and authorized for processing, signifying its readiness for operational use.

DInitiation Phase

The Initiation Phase involves defining the need for a system, conducting feasibility studies, and establishing initial security requirements, but does not involve the physical configuration, testing, or installation.

Concept tested: SDLC phases - Implementation Phase

Source: https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/final

Topics

#SDLC phases#Implementation phase#System deployment#Authorization to Operate (ATO)

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice