ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During backlog refinement for a new cloud-based file storage service, you propose the following requirement: "The system shall encrypt all files at rest using AES-256 keys managed by the organization's HSM." According to secure requirement practices, how should this statement be classified and where is it most appropriately documented to ensure later verification?
An operational continuity requirement that belongs exclusively in disaster recovery procedures and deployment scripts
A compliance requirement derived from privacy legislation that is tracked only under data access provisioning records
A functional security requirement that should be expressed solely as a user story in the product backlog
A non-functional security requirement that should be recorded as a quality attribute and referenced in the Security Requirement Traceability Matrix
Encryption at rest specifies a quality the system must possess rather than an end-user capability, so it is a non-functional security requirement. Non-functional requirements are commonly captured as system quality attributes and linked in the Security Requirement Traceability Matrix (SRTM), which allows the team to trace the requirement through design, implementation, and testing. Recording it only in a user story, deployment script, or compliance register would make systematic traceability and validation more difficult.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AES-256 encryption?
Open an interactive chat with Bash
What is a Hardware Security Module (HSM)?
Open an interactive chat with Bash
What is the Security Requirement Traceability Matrix (SRTM)?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .