Study. uk . com
  1. Home
  2. All questions
  3. Question 475

CISSP study material · question 475 of 500

OWASP names a factor that contributes to insecure design and explains why the design was never made secure enough. What is it?

  1. No dedicated security architect on the team, so no design review took place.
  2. No inventory of third-party components, so their design could not be assessed.
  3. No business risk profiling of the software, so nobody determined what level of security design was required.
  4. No automated testing in the build pipeline, so design defects were never detected.
Show the answer

Answer: C. No business risk profiling of the software, so nobody determined what level of security design was required.

Where nobody profiled what the business stood to lose, nobody settled how much security the design owed, and the design came out short.

Source: OWASP Top 10 A06:2025 (OWASP) — OWASP Top 10:2025 A06 Insecure Design > Description

Challenge yourself on this topic → Study as cards