Study. uk . com
  1. Home
  2. All questions
  3. Question 480

CISSP study material · question 480 of 500

A vendor markets a tool it says will deliver secure design for any application. How does OWASP characterise secure design?

  1. As a design review gate performed before implementation begins.
  2. As an attribute of the architecture that can be certified independently.
  3. As a culture and methodology that continually evaluates threats; it is neither an add-on nor a tool.
  4. As a checklist that a tool can verify once per release.
Show the answer

Answer: C. As a culture and methodology that continually evaluates threats; it is neither an add-on nor a tool.

OWASP calls secure design a culture and methodology that continually evaluates threats and tests the design, and says it is neither an add-on nor a tool.

Source: OWASP Top 10 A06:2025 (OWASP) — OWASP Top 10:2025 A06 Insecure Design > Secure Design

Challenge yourself on this topic → Study as cards