- Home
- All questions
- Question 480
CISSP study material · question 480 of 500
A vendor markets a tool it says will deliver secure design for any application. How does OWASP characterise secure design?
Show the answer
Answer: C. As a culture and methodology that continually evaluates threats; it is neither an add-on nor a tool.
OWASP calls secure design a culture and methodology that continually evaluates threats and tests the design, and says it is neither an add-on nor a tool.
Source: OWASP Top 10 A06:2025 (OWASP) — OWASP Top 10:2025 A06 Insecure Design > Secure Design