ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a due-diligence review, you must confirm that a software supplier's open-source governance aligns with ISO/IEC 5230:2020 (the OpenChain specification). Which practice would most clearly demonstrate compliance with this standard and thereby strengthen your organization's software supply chain risk management posture?
ISO/IEC 27001 certification for the supplier's data-center infrastructure
A documented open-source policy accompanied by mandatory license-compliance training for all developers
Encryption of every software bill of materials (SBOM) file using AES-256 before distribution
Monthly dynamic application security testing of the supplier's production environment
ISO/IEC 5230 (OpenChain) defines the minimum requirements for a quality open-source license compliance program. Two of its core clauses mandate that an organization maintain a documented open-source policy and ensure all relevant personnel receive appropriate training or can prove equivalent competence. This combination shows that the supplier has formally defined how open-source software may be introduced and managed and that staff understand and follow those rules-directly evidencing conformity with the standard. The other options, while potentially good security measures, are not requirements of ISO/IEC 5230 and do not in themselves prove license-compliance governance as specified by the standard.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is ISO/IEC 5230 (OpenChain) and why is it important?
Open an interactive chat with Bash
What are the core requirements of a documented open-source policy under ISO/IEC 5230?
Open an interactive chat with Bash
What does mandatory license-compliance training entail under ISO/IEC 5230?
Open an interactive chat with Bash
What is the OpenChain specification (ISO/IEC 5230)?
Open an interactive chat with Bash
Why is mandatory open-source license-compliance training important?
Open an interactive chat with Bash
What is a Software Bill of Materials (SBOM) and how does it relate to ISO/IEC 5230?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .