ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a due-diligence review, you must confirm that a software supplier's open-source governance aligns with ISO/IEC 5230:2020 (the OpenChain specification). Which practice would most clearly demonstrate compliance with this standard and thereby strengthen your organization's software supply chain risk management posture?
Encryption of every software bill of materials (SBOM) file using AES-256 before distribution
A documented open-source policy accompanied by mandatory license-compliance training for all developers
ISO/IEC 27001 certification for the supplier's data-center infrastructure
Monthly dynamic application security testing of the supplier's production environment
ISO/IEC 5230 (OpenChain) defines the minimum requirements for a quality open-source license compliance program. Two of its core clauses mandate that an organization maintain a documented open-source policy and ensure all relevant personnel receive appropriate training or can prove equivalent competence. This combination shows that the supplier has formally defined how open-source software may be introduced and managed and that staff understand and follow those rules-directly evidencing conformity with the standard. The other options, while potentially good security measures, are not requirements of ISO/IEC 5230 and do not in themselves prove license-compliance governance as specified by the standard.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is ISO/IEC 5230 (OpenChain) and why is it important?
Open an interactive chat with Bash
What are the core requirements of a documented open-source policy under ISO/IEC 5230?
Open an interactive chat with Bash
What does mandatory license-compliance training entail under ISO/IEC 5230?
Open an interactive chat with Bash
What is the OpenChain specification (ISO/IEC 5230)?
Open an interactive chat with Bash
Why is mandatory open-source license-compliance training important?
Open an interactive chat with Bash
What is a Software Bill of Materials (SBOM) and how does it relate to ISO/IEC 5230?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .