ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Early in a healthcare web-application project, the CISO requests a document that will serve as the authoritative baseline describing the system's security requirements, chosen controls, responsible roles, and the schedule for implementing them so auditors can track progress throughout the lifecycle. Which security document best fulfills this request?
The security (system security) plan is created at the outset of a project to capture the system's overall security requirements, the specific controls selected to meet them, assigned responsibilities, and implementation milestones. It establishes the baseline against which security progress and compliance are measured during development and operations.
A risk assessment report records identified threats, vulnerabilities, and their potential impact but does not prescribe how controls will be implemented or managed over time.
An incident response plan focuses on procedures for detecting, responding to, and recovering from security incidents, not on documenting baseline controls and schedules.
A verification and validation test report summarizes testing results after tests have been executed; it is evidence of control effectiveness, not the planning artifact that defines those controls. Therefore, producing a comprehensive security plan is the appropriate action.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a System Security Plan (SSP)?
Open an interactive chat with Bash
Why is a Risk Assessment Report not sufficient as a baseline security plan?
Open an interactive chat with Bash
How does an Incident Response Plan differ from a Security Plan?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .