ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While finalizing the SLA for a cloud-hosted payment application, you need a quantifiable clause proving that the provider's administrators are both formally qualified and kept current on security best practices. Which of the following staffing requirements BEST meets this goal?
The provider shall appoint a dedicated chief security officer (CSO) responsible for ensuring overall compliance with the SLA's security provisions.
One hundred percent of system administrators must hold an industry-recognized security certification (such as CISSP or CISA) and complete secure-operations training every year, with annual audit results provided to the customer.
The provider shall maintain a documented access-control matrix for privileged accounts and have it reviewed internally on a quarterly basis.
All new administrative hires must pass a criminal background check and be re-screened every five years, with summary results reported to the customer.
Stipulating that all system administrators hold an industry-recognized security certification and complete annual secure-operations training makes personnel competence measurable and auditable. It ties directly to administrator qualifications and ongoing education. Background checks, access-control documentation, and designating a security officer are important but do not, by themselves, confirm that every administrator possesses and maintains current security expertise.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are industry-recognized security certifications like CISSP and CISA?
Open an interactive chat with Bash
Why is annual secure-operations training important for cloud service administrators?
Open an interactive chat with Bash
Why is an annual audit of training and certifications important for customers using cloud services?
Open an interactive chat with Bash
What are industry-recognized security certifications like CISSP or CISA?
Open an interactive chat with Bash
Why is annual secure-operations training for administrators important?
Open an interactive chat with Bash
How are annual audits of administrator qualifications beneficial to SLA compliance?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)