Security Software Development Life Cycle (SDLC) expects application code to be written in a consistent manner to allow ease of auditing and which of the following?
It is A
OWASP Secure Code Review Guide page 23 states the following:
Who Should Perform Secure Code ReviewsSome organizations assume secure code review can be a job for a security or risk-analysis team member. How-ever all developers need to understand the exposure points of their applications and what threats exist for theirapplications.Many companies have security teams that do not have members with coding backgrounds, which can makeinteractions with development teams challenging. Because of this development teams are usually skeptical ofsecurity input and guidance. Security teams are usually willing to slow things down to ensure confidentialityand integrity controls are in place while developers are face with pressure from business units they support tocreate and update code as quickly as possible."
A. Protecting
Consistently written and well-documented code makes it easier to review and audit for security vulnerabilities and compliance with security standards and best practices. It helps protect the application against potential security threats and risks.
The Security Software Development Life Cycle (SDLC) expects application code to be written in a consistent manner to allow ease of auditing and A. Protecting. A secure SDLC involves integrating security testing and activities into the software development process, ensuring that security is a component of every phase of the SDLC.
This includes writing security requirements alongside functional requirements, performing architecture risk analysis during the design phase, and conducting code reviews during coding and building to protect the application code.
C is the anwer
The Security Software Development Life Cycle (SDLC) expects consistent code to allow ease of auditing and enhancing, option C.
Consistent, standardized code makes it easier to maintain, update, modify, and add new functionality to an application over time.
This matches enhancing.
Protecting, copying, and executing code are not directly enabled by consistent coding. Though protection may be an indirect benefit.
A key goal of disciplined secure SDLC processes is to produce uniform code that is straightforward to audit for security and quality while also positioning the application to be enhanced with new features over time.
Therefore, enhancing is the secondary goal, along with auditing, that consistent code practices aim to achieve. This makes option C correct.
The Security Software Development Life Cycle (SDLC) expects application code to be written in a consistent manner to allow ease of auditing and enhancing1. This is because writing code consistently helps with code readability, maintainability, and ease of auditing.
Vote for C. Enhancing. When a new or better programming style / technique / methodology was found, it is easier to search the entire program and change them (Find and replace) if the codes are consistent.
Security Software Development Life Cycle (SDLC) expects application code to be written in a consistent manner to allow ease of auditing and protecting the integrity of the code, the application, and the data it handles. This includes following a consistent process for code development, testing, and deployment, using secure coding practices and guidelines, and implementing appropriate security controls and monitoring mechanisms.
B. Copying, C. Enhancing and D. executing are not the correct answer in this context as the Security Software Development Life Cycle (SDLC) is a process, not an action.
When the code is consistent, it's easier to understand and test.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
SSimko
10 months agoCoolCat22
11 months, 2 weeks agoSoleandheel
11 months, 2 weeks agoSoleandheel
11 months, 2 weeks agoInclusiveSTEAM
1 year, 1 month agoBLADESWIFTKNIFE
1 year, 2 months agoliebeskind
1 year, 6 months agoDJOEK
1 year, 10 months agojackdryan
1 year, 6 months agooudmaster
1 year, 11 months agoJamati
2 years ago