ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization integrates a third-party payment SDK maintained by an external vendor. To mitigate supply-chain risk, which contractual security requirement is MOST important to ensure newly discovered critical vulnerabilities are addressed in a timely manner?
Require the vendor to remediate critical vulnerabilities within an agreed SLA, such as providing a patch or mitigation within 30 days of disclosure.
Require the vendor to allow a one-time source-code review before the initial deployment.
Require the vendor to deliver a summary of its annual third-party penetration test results.
Require the vendor to publish performance benchmarks for every SDK release.
The most effective way to manage ongoing risk in a third-party component is to bind the supplier to an explicit vulnerability-response service level agreement (SLA). An SLA that defines deadlines for patching or providing mitigations (for example, within 30 days for critical issues) gives the customer enforceable leverage to keep the component secure throughout its lifecycle. Requiring only an annual penetration-test report or a one-time code review offers limited, point-in-time assurance and does not guarantee prompt remediation when new flaws emerge. Performance benchmarks have no bearing on security and therefore do not reduce the risk of unpatched vulnerabilities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a supply-chain risk in the context of software development?
Open an interactive chat with Bash
What is a Service Level Agreement (SLA) in the context of cybersecurity?
Open an interactive chat with Bash
Why is an agreed SLA more important than a one-time source code review for mitigating supply-chain risks?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .