Study. uk . com
  1. Home
  2. All questions
  3. Question 73

CISSP study material · question 73 of 500

A financial services firm runs three delivery groups: one on a waterfall life cycle, one on Scrum, and one on continuous delivery. The CISO wants a single consistent set of secure-development expectations across all three without forcing them onto one common life-cycle model. Which approach fits the Secure Software Development Framework (SSDF) as it is published?

  1. Layer the SSDF practices onto each group's existing life cycle, since the framework is written to be added to any model.
  2. Apply the SSDF only to the continuous delivery group, because the framework describes pipeline automation controls.
  3. Replace each group's life cycle with the SSDF, since the framework defines its own end-to-end development process.
  4. Standardise all three groups on one iterative life cycle first, because the framework assumes agile delivery cadences.
Show the answer

Answer: A. Layer the SSDF practices onto each group's existing life cycle, since the framework is written to be added to any model.

SSDF is deliberately life-cycle agnostic and layers onto whatever model a team already runs. It supplies practices, so replacing an existing life cycle with it misreads its purpose.

Source: NIST SP 800-218 (NIST) — SP 800-218 > Abstract

Challenge yourself on this topic → Study as cards