Study. uk . com
  1. Home
  2. All questions
  3. Question 477

CISSP study material · question 477 of 500

Which activities does OWASP place in the requirements and resource management part of secure design? Choose three.

  1. Negotiating with the business the protection needed for each data asset's confidentiality, integrity, availability and authenticity.
  2. Considering how exposed the application will be and whether tenants need segregating.
  3. Planning and negotiating the budget across design, build, testing and operation, including security activities.
  4. Selecting the static analysis tooling the pipeline will run.
Show the answer

Answer: A. Negotiating with the business the protection needed for each data asset's confidentiality, integrity, availability and authenticity.
B. Considering how exposed the application will be and whether tenants need segregating.
C. Planning and negotiating the budget across design, build, testing and operation, including security activities.

OWASP's requirements work covers negotiating business and protection requirements for data assets, considering exposure and tenant segregation, and budgeting for design, build, testing and operation including security activities.

Source: OWASP Top 10 A06:2025 (OWASP) — OWASP Top 10:2025 A06 Insecure Design > Requirements and Resource Management

Challenge yourself on this topic → Study as cards