ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A development team is searching for a NIST publication that lays out concrete security activities-such as capturing security requirements, performing design reviews, conducting code analysis, verifying controls, and confirming secure release-explicitly aligned to each phase of the software development life cycle. Which NIST document most directly meets this need?
NIST SP 800-64 Revision 2 - Security Considerations in the System Development Life Cycle
NIST Cybersecurity Framework (CSF)
NIST Secure Software Development Framework (SSDF) - SP 800-218
NIST Special Publication 800-64 Revision 2, "Security Considerations in the System Development Life Cycle," is organized around the classic SDLC phases (Initiation; Development/Acquisition; Implementation/Assessment; Operation/Maintenance; and Disposal). For every phase it prescribes specific security tasks such as requirements identification, architectural risk analysis, code reviews, security testing, change control, and secure disposal activities.
In contrast, the Secure Software Development Framework (SSDF) in SP 800-218 provides a set of security practices grouped into Prepare, Protect, Produce, and Respond categories, but it intentionally does not tie those practices to particular SDLC phases. The Risk Management Framework (SP 800-37) focuses on system authorization and continuous monitoring, while the Cybersecurity Framework offers high-level organizational risk-management guidance. Therefore, SP 800-64 Rev. 2 is the most appropriate choice for phase-specific secure-development tasks.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the SDLC and why is it significant in software security?
Open an interactive chat with Bash
How does NIST SP 800-64 differ from NIST SP 800-218 (SSDF)?
Open an interactive chat with Bash
What are some key security activities outlined in NIST SP 800-64 for the SDLC phases?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .