ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

A development team is integrating a third-party SaaS CRM. The master services agreement specifies a 99.9 % availability service-level agreement and obligates the provider to notify the customer of any security breach within 48 hours. When analysing compliance, how should these clauses be handled in the project's security requirements baseline?

  • View them only as non-binding recommendations since they are not statutory law.

  • Document them as legal compliance requirements and map them in the security requirement traceability matrix.

  • Disregard them once internal security testing shows the code is secure, because uptime is purely operational.

  • Treat them as functional security requirements that belong solely in user stories during sprint planning.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot