- Home
- All questions
- Question 73
CISSP study material · question 73 of 500
A financial services firm runs three delivery groups: one on a waterfall life cycle, one on Scrum, and one on continuous delivery. The CISO wants a single consistent set of secure-development expectations across all three without forcing them onto one common life-cycle model. Which approach fits the Secure Software Development Framework (SSDF) as it is published?
Show the answer
Answer: A. Layer the SSDF practices onto each group's existing life cycle, since the framework is written to be added to any model.
SSDF is deliberately life-cycle agnostic and layers onto whatever model a team already runs. It supplies practices, so replacing an existing life cycle with it misreads its purpose.
Source: NIST SP 800-218 (NIST) — SP 800-218 > Abstract