CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 878


Which of the following BEST minimizes information security risk in deploying applications to the production environment?

Show Answer
Correct Answer: BD

Integrating security controls in each phase of the life cycle best minimizes information security risk in deploying applications to the production environment. By addressing security concerns at every stage of the software development life cycle, any potential vulnerabilities or threats can be identified and mitigated early on. This holistic approach ensures that the final product is robust and secure, thus reducing the risk when the application is eventually deployed to production.

Discussion

12 comments
Sign in to comment
AaronS1990Option: D
Sep 13, 2023

I agree this is definitely D. Every other question of this nature emphasises the importance of implementing security as often and early as possible in development.

EwuniaOption: D
Aug 10, 2023

i will go with D

POWNEDOption: B
Jan 31, 2024

You have to look at the scope of the question! It is specifically asking what is BEST for deployment to production. Yes Implementing security through the SDLC is the MOST beneficial, but for the scope of the question it is not the best. A properly designed change management process is the best action when it comes to deploying anything new.

AidanSunOption: D
Aug 8, 2023

D should be the correct answer.

AlexJacobsonOption: B
Jan 28, 2024

Well, I'm not so sure it's D. The question is about the deployment to production (from development, I assume). Option D considers SDLC, so it would reduce the risk of introducing vulnerabilities in the application itself. And while one can argue that by increasing the security of the application that you're deploying in production effectively lowers the risk in general, the question is still about the PROCESS of moving something from one environment to another (i.e. the managing the changes in the environment), not the SDLC. So I'm going with B on this one.

AlexJacobson
Jan 28, 2024

Then again, SDLC covers all phases and would include secure implementation and maintenance...So it can be D as well... Tricky question.

SaisharanOption: D
Aug 21, 2023

Option D

6and0Option: D
Sep 22, 2023

D. Integrating security controls in each phase of the life cycle

richck102Option: D
Oct 3, 2023

D. Integrating security controls in each phase of the life cycle

Marcelus1714Option: B
Feb 17, 2024

It talk about "risk" (Not "vulnerabilities") and "in deploying", so I would agree the marked answer. If was talking about to detect vulnerabilities in the code, definetly would be D, but B is more high level and related to risks

Marcelus1714
Feb 17, 2024

and in the change process D can be included

oluchecpointOption: B
Mar 17, 2024

Option B

yottabyteOption: B
Mar 21, 2024

I will go for B with this one, if the question asks while developing, then the answer will be D, but when the question says deploying, the answer should be B.

03allenOption: B
Jul 18, 2024

No doubt, it's B.