ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During project kickoff for a new healthcare microservice, the project manager asks you to deliver the application's security plan before coding begins. To meet the primary purpose of this document within the secure SDLC, which content should it include that would not be found in incident response or test reports?
A list of vulnerabilities discovered during penetration testing with target remediation dates
Step-by-step procedures to remove malware detected in production systems
A mapping of planned security controls to the specific project roles responsible for implementing them
A comprehensive schedule indicating how long patient data must be retained before secure destruction
A security plan is a forward-looking document created early in the lifecycle to describe how security will be managed throughout the project. It defines the applicable security controls and, critically, assigns roles and responsibilities for implementing and maintaining those controls. Malware eradication procedures belong in an incident response plan, post-test vulnerability lists appear in verification reports, and detailed retention schedules are part of data disposition or decommissioning documentation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the primary purpose of a security plan in the Secure SDLC?
Open an interactive chat with Bash
Why are roles and responsibilities critical in a security plan?
Open an interactive chat with Bash
How does a security plan differ from an incident response plan?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .