ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization is procuring a third-party API that will be embedded in a public-facing service. To satisfy secure-supply-chain objectives, the contract must spell out how future security events are handled. Which requirement BEST enables coordinated vulnerability response and reporting if the supplier later uncovers a critical flaw in the API?
Require the supplier to notify your organization of any discovered vulnerabilities within 24 hours and jointly establish a timeline for patch release and mitigation.
Oblige the supplier to submit quarterly security summary reports detailing all issues fixed in the previous period.
Include a warranty stating the delivered software will be free of security vulnerabilities at the time of acceptance.
Mandate that the supplier's development processes align with ISO/IEC 27034 secure development lifecycle practices.
The most effective way to coordinate a future security incident with a supplier is to obligate that supplier to notify the acquirer quickly and to work jointly on remediation timelines. A time-bound notification clause (for example, within 24 hours) coupled with an agreed patch or mitigation schedule ensures the acquirer can assess risk, initiate its own response, and keep stakeholders informed. Merely stating that the vendor follows a secure development lifecycle, provides periodic reports, or warrants bug-free software does not guarantee timely disclosure or joint action when a new vulnerability emerges. Warranty language and quarterly reports are valuable, but neither addresses the urgent coordination required during an active security incident; a prompt disclosure and collaborative mitigation plan does.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is a 24-hour notification clause critical in vulnerability management?
Open an interactive chat with Bash
What is ISO/IEC 27034, and why isn’t it sufficient for vulnerability response?
Open an interactive chat with Bash
Why are warranties and quarterly reports less effective for critical flaw handling?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .