As part of a new customer-facing web application, a development team has incorporated dozens of open-source libraries drawn from public repositories. The security manager must ensure these third-party components remain secure throughout the system's life cycle despite limited resources. Which action BEST satisfies this requirement within modern secure-development best practices?
Forking all open-source components and maintaining them internally
Avoiding the use of all open-source software
Implementing a software composition analysis process with ongoing vulnerability monitoring
Using only open-source libraries that have been extensively peer-reviewed
The correct answer is implementing a software composition analysis process with ongoing vulnerability monitoring. This approach inventories the open-source components in use, maps them to known vulnerabilities, and continuously tracks new CVE disclosures so patches or upgrades can be applied promptly.
Avoiding the use of all open-source software is unrealistic; more than 95 percent of commercial codebases already contain open-source components, and these can be used safely with proper controls.
Using only extensively peer-reviewed libraries improves initial selection but does not address newly discovered flaws; continuous monitoring is still required.
Forking all open-source components and maintaining them internally imposes a significant maintenance burden-teams must back-port every security fix themselves-making it unsustainable for most organizations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is software composition analysis (SCA)?
Open an interactive chat with Bash
Why is ongoing vulnerability monitoring important for open-source components?
Open an interactive chat with Bash
What are the challenges of forking and maintaining open-source components internally?
Open an interactive chat with Bash
ISC2 CISSP
Software Development Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .