ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your team is drafting security requirements for a new cloud-based CRM that will collect and store personal information about European Union residents on servers hosted in the United States. Which source represents a legally binding regulatory mandate that must be incorporated into the project's security requirements?
ISO/IEC 27034 Secure Development Framework
OWASP Application Security Verification Standard (ASVS)
Payment Card Industry Data Security Standard (PCI DSS)
The General Data Protection Regulation (GDPR) is an EU law that imposes legal obligations on any organization processing personal data of EU residents, including strict controls on cross-border transfers, consent, breach notification, and privacy by design. ISO/IEC 27034 and OWASP ASVS are voluntary best-practice frameworks, while PCI DSS is an industry standard contractually required by card brands but not a government statute. Therefore, only GDPR is a regulatory authority source that the development team is legally required to follow.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is GDPR and why is it legally binding?
Open an interactive chat with Bash
What is the difference between GDPR and PCI DSS?
Open an interactive chat with Bash
What does 'privacy by design' mean under GDPR?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .