ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While drafting the security testing strategy for a new payment-processing platform, the product security lead is evaluating industry standards. The team wants prescriptive guidance on integrating security throughout the software development lifecycle, including creation of an Application Security Control (ASC) library. Which standard best meets this need?
Open Source Security Testing Methodology Manual (OSSTMM)
NIST SP 800-115 Technical Guide to Information Security Testing
OWASP Application Security Verification Standard (ASVS)
ISO/IEC 27034 is an international standard titled "Information technology - Security techniques - Application security." Part 1 of the series introduces the Application Security Management Process and the concept of an Organization Normative Framework that contains an Application Security Control (ASC) Library. The standard is designed to weave security into every phase of the SDLC and to provide reusable security controls. The OWASP ASVS offers detailed verification requirements but is not an ISO standard and lacks an ASC library concept. OSSTMM focuses on operational security and penetration-testing metrics rather than life-cycle integration. NIST SP 800-115 gives guidance for technical testing activities, not for establishing ongoing application security governance across development phases.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is ISO/IEC 27034?
Open an interactive chat with Bash
What is the Application Security Control (ASC) Library?
Open an interactive chat with Bash
How does ISO/IEC 27034 differ from OWASP ASVS?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .