ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While preparing a bid, your software company must show that its development environment operates under a formally defined, independently auditable information security management system that follows a risk-based approach and supports continuous improvement. Which international standard best satisfies this requirement?
ISO/IEC 29147 - guidelines for coordinated vulnerability disclosure
ISO/IEC 27001 - requirements for an information security management system that can be formally certified
ISO 9001 - framework for quality management and continual improvement of products and services
ISO/IEC 12207 - processes for software acquisition, development, operation, and maintenance
ISO/IEC 27001 is the only option that defines mandatory requirements for establishing, implementing, maintaining, and continually improving an organization-wide Information Security Management System (ISMS). Because it includes a certification scheme audited by accredited bodies, it provides external assurance that security governance and risk management are systematically applied across all people, processes, and technology involved in software development.
ISO/IEC 12207 focuses on describing software lifecycle processes but does not create an auditable ISMS. ISO/IEC 29147 addresses vulnerability disclosure procedures, and ISO 9001 targets quality management, not information security. Therefore, these alternatives would not meet the customer's request for proof of a certified ISMS.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Information Security Management System (ISMS)?
Open an interactive chat with Bash
Why is ISO/IEC 27001 certification preferred for demonstrating security governance?
Open an interactive chat with Bash
How does ISO/IEC 27001 differ from ISO/IEC 12207?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .