CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 362


A company is moving from the V model to Agile development. How can the information security department BEST ensure that secure design principles are implemented in the new methodology?

Show Answer
Correct Answer: A

To ensure that secure design principles are implemented in an Agile development methodology, it is best to integrate security requirements directly into the development process. By capturing information security requirements in mandatory user stories, the security considerations are inherently part of the development cycle. This ensures that security is continuously addressed during each iteration, making it an integral part of the product development lifecycle rather than a separate or afterthought activity.

Discussion

8 comments
Sign in to comment
inmymind84Option: A
Sep 21, 2022

Assessment cannot guarantee that security principles will be implemented :). A is fine.

jackdryan
May 14, 2023

A is correct

JAckThePipOption: C
Oct 6, 2022

Answer is C https://www.breachlock.com/agile-security-devops/

Cww1Option: C
Sep 17, 2022

im going C

wedsoOption: C
Jan 7, 2023

sprint model

ACunningPlanOption: A
Apr 6, 2023

Ha ha, if they did assessment every Sprint it wouldn't be long before nobody was taking it seriously.

WiDeBarulhoOption: A
Oct 25, 2022

If they're moving from Agile development model clearly they don't want to be doing tests after each sprint as that is one of the downsides of Agile. Therefore it is critical that security requirements are properly captured before moving to a new methodology.

franbarpro
Oct 26, 2022

A company is moving from the V model to Agile development

SoleandheelOption: A
Dec 16, 2023

A. Information security requirements are captured in mandatory user stories. By capturing information security requirements in mandatory user stories, the security considerations are integrated into the development process, ensuring that secure design principles are addressed throughout the Agile development lifecycle. This approach aligns with the Agile principle of satisfying customers through early and continuous delivery of valuable work, as well as the 12 core principles of Agile, which emphasize the importance of integrating security requirements into the development process to ensure sustainable and secure efforts.

klarakOption: C
May 6, 2024

Rule 1: ANSWER THE ACTUAL QUESTION. It asks has INFORMATION SECURITY can solve this scenario which means C. It can't be A because user stories are a QA/QC function