ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During requirements gathering for a U.S. federal agency's new citizen-services portal, the security engineer wants to embed security early in the SDLC. Which task should be performed in this phase to meet that goal?
Conduct red-team penetration tests against the first working prototype to uncover coding flaws.
Apply Center for Internet Security benchmark settings to the operating system images before deployment.
Compile and document system-specific security requirements by mapping applicable laws, regulations, and baseline controls to functional specifications.
Configure and tune security information and event management (SIEM) correlation rules for production monitoring.
The requirements-gathering phase is where stakeholders identify and document what the system must do and how it must be protected. According to NIST SP 800-64, security practitioners should derive security functional and assurance requirements from applicable laws, regulations, and control baselines and include them in the overall system specification. Activities such as penetration testing, operating-system hardening, and SIEM rule tuning occur in later SDLC phases (testing, implementation, and operations, respectively). Therefore, documenting system-specific security requirements up front is the action that integrates security at this earliest stage.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SDLC and why is it important for system development?
Open an interactive chat with Bash
Why is embedding security early in the SDLC crucial?
Open an interactive chat with Bash
What does NIST SP 800-64 recommend for security during requirements gathering?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .