ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization needs a repeatable approach for assessing the effectiveness of technical, physical, and operational controls during penetration tests across its global data centers. Which standard best fits this requirement when you are building the security testing strategy?
ISO/IEC 27034 Application Security standard
Open Source Security Testing Methodology Manual (OSSTMM)
NIST Special Publication 800-64
OWASP Application Security Verification Standard (ASVS)
The Open Source Security Testing Methodology Manual (OSSTMM) is a comprehensive framework for operational security testing. It provides detailed, scientific procedures for evaluating network, wireless, telecommunications, human, and physical security controls and produces consistently structured, quantitative test results that facilitate repeatable assessments.
ISO/IEC 27034 centers on integrating security into the application development life-cycle rather than defining penetration-testing procedures. NIST SP 800-64 (now withdrawn) offered SDLC-oriented security guidance but no concrete penetration-testing methodology. The OWASP Application Security Verification Standard (ASVS) is focused narrowly on web-application control verification, not on broader operational or physical security domains.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Open Source Security Testing Methodology Manual (OSSTMM)?
Open an interactive chat with Bash
How does OSSTMM compare to ISO/IEC 27034 for penetration testing?
Open an interactive chat with Bash
What makes OSSTMM a preferred security testing standard over OWASP ASVS?
Open an interactive chat with Bash
What is OSSTMM, and why is it important?
Open an interactive chat with Bash
How does OSSTMM differ from ISO/IEC 27034?
Open an interactive chat with Bash
What makes OSSTMM a better fit for penetration testing than OWASP ASVS?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .