SSCP · Question #1127
From a security standpoint, the product development life cycle consists of which of the following?
The correct answer is F. All of the items listed. A comprehensive security-focused product development life cycle integrates security considerations across all phases, from initial design to final accreditation.
Question
From a security standpoint, the product development life cycle consists of which of the following?
Options
- ACode Review
- BCertification
- CAccreditation
- DFunctional Design Review
- ESystem Test Review
- FAll of the items listed
How the community answered
(35 responses)- A3% (1)
- B3% (1)
- D6% (2)
- F89% (31)
Why each option
A comprehensive security-focused product development life cycle integrates security considerations across all phases, from initial design to final accreditation.
Code review is only one specific activity and does not encompass the entire security product development life cycle, which includes design, testing, and formal approval stages.
Certification is a formal process of technical evaluation but does not cover the complete spectrum of security activities during product development, such as design or coding practices.
Accreditation is a formal management decision to operate a system, which is a post-certification step and doesn't cover the full development lifecycle activities like design or testing.
Functional design review is an important early-stage security consideration but does not address the security aspects of coding, testing, or formal authorization.
System test review focuses on the testing phase for security but omits crucial security activities that occur during the design, coding, and formal approval stages of product development.
A secure product development life cycle (SDLC) integrates security activities throughout all phases, meaning elements like functional design review (D) for early security considerations, code review (A) for implementation quality, and system test review (E) for validation are crucial. Additionally, formal processes like certification (B) and accreditation (C) are often part of the security assurance lifecycle for products, ensuring a comprehensive security approach.
Concept tested: Secure Software Development Lifecycle (SSDLC)
Source: https://learn.microsoft.com/en-us/security/engineering/dev-sec-ops
Topics
Community Discussion
No community discussion yet for this question.