ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization plans to adopt the OWASP Software Assurance Maturity Model (SAMM) to guide improvements to its secure software development process. According to SAMM's recommended rollout approach, which activity should the team perform first before setting any security objectives or defining an improvement roadmap?
Launch mandatory secure coding training for all development staff across the organization
Introduce a public bug-bounty program to discover previously unknown vulnerabilities
Perform a baseline self-assessment to measure current maturity against SAMM security practices
Deploy automated static application security testing (SAST) in every continuous integration pipeline
OWASP SAMM stresses that an organization must start by understanding where it currently stands. The model's initial step is a structured self-assessment that scores the maturity of each SAMM security practice. This baseline reveals strengths and gaps, allowing the team to set realistic targets and prioritize subsequent improvement activities. Deploying static analysis, launching secure coding training, or running a bug-bounty program are valuable tactics, but SAMM recommends pursuing such enhancements only after the initial assessment clarifies which practices need attention and at what maturity level.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the OWASP Software Assurance Maturity Model (SAMM)?
Open an interactive chat with Bash
Why is a baseline self-assessment critical in SAMM?
Open an interactive chat with Bash
How does SAMM differ from automated tools like SAST?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .