ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A development team is selecting a security testing standard to underpin their application assessment process. They choose the Open Source Security Testing Methodology Manual (OSSTMM) because it will let them quantify test results across different operational areas in a consistent way. According to OSSTMM, which feature specifically enables this quantitative comparison of security posture?
A focus on black-box web application assessments to enumerate OWASP Top 10 vulnerabilities.
Certification as a mandatory, legally binding standard under ISO and PCI DSS regulations.
A requirement that all vulnerability severities be expressed with the Common Vulnerability Scoring System (CVSS).
Its use of Risk Assessment Values (RAV) within the Operational Security Metrics model to assign numerical scores to test findings.
OSSTMM distinguishes itself from many other security testing standards by including a formalized set of numerical metrics called the Risk Assessment Values (RAV) within its Operational Security Metrics (OSM) model. Testers assign RAV scores to findings in each operational security channel (e.g., Human, Physical, Wireless, Telecommunications, Data) and factor in limitations and controls to calculate a Security Trust Level (STL). These numbers provide a uniform basis for comparing security posture across disparate systems or environments. The other options describe characteristics that are either outside OSSTMM's scope (exclusive web-application testing), factually incorrect (OSSTMM is not a legally mandated compliance framework), or belong to different scoring systems (CVSS, not RAV).
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Risk Assessment Values (RAV) in OSSTMM?
Open an interactive chat with Bash
How does OSSTMM's Operational Security Metrics (OSM) model work?
Open an interactive chat with Bash
Why is OSSTMM different from other security testing standards?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .