- Home
- All questions
- Question 74
CISSP study material · question 74 of 500
A product group adopting the Secure Software Development Framework (SSDF) scans dependencies every build and patches reported flaws within days, yet its vulnerability count returns to the same level each release. An architect argues the programme still misses one of the framework's stated objectives. Which objective is the group overlooking?
Show the answer
Answer: A. Identifying and addressing the root causes that keep producing the same classes of vulnerability.
SSDF targets three outcomes: fewer vulnerabilities released, reduced impact of those exploited, and root causes fixed so the same defects stop recurring. Faster patching alone leaves causes untouched.
Source: NIST SP 800-218 (NIST) — SP 800-218 > Abstract