Study. uk . com
  1. Home
  2. All questions
  3. Question 74

CISSP study material · question 74 of 500

A product group adopting the Secure Software Development Framework (SSDF) scans dependencies every build and patches reported flaws within days, yet its vulnerability count returns to the same level each release. An architect argues the programme still misses one of the framework's stated objectives. Which objective is the group overlooking?

  1. Identifying and addressing the root causes that keep producing the same classes of vulnerability.
  2. Increasing the frequency of dependency scanning at each stage of the build pipeline.
  3. Recording each vulnerability's severity rating in a central defect register for audit.
  4. Reducing the mean time to patch each reported vulnerability across the production estate.
Show the answer

Answer: A. Identifying and addressing the root causes that keep producing the same classes of vulnerability.

SSDF targets three outcomes: fewer vulnerabilities released, reduced impact of those exploited, and root causes fixed so the same defects stop recurring. Faster patching alone leaves causes untouched.

Source: NIST SP 800-218 (NIST) — SP 800-218 > Abstract

Challenge yourself on this topic → Study as cards