CISSP Software Development Security Practice Question
An organization is planning to acquire a new SaaS application for customer relationship management. Which THREE of the following should be included in the vendor security assessment?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reviewing the vendor's security certifications (e.g., SOC 2, ISO 27001)
Reviewing the vendor's security certifications (e.g., SOC 2), assessing their incident response process, and requesting a Software Bill of Materials (SBOM) are key steps. License compliance is important but not directly security, and employee training is internal to the vendor but less critical than the others.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Checking license compliance for open source components
Why it's wrong here
While important for legal and governance purposes, checking license compliance for open source components primarily addresses intellectual property and contractual obligations, not the direct security posture of the SaaS application. This activity helps mitigate legal risks like copyright infringement or non-compliance with licensing terms, but it does not directly assess the presence of security vulnerabilities or the effectiveness of the vendor's security controls. Therefore, it is not a primary security due diligence activity during SaaS acquisition.
- ✓
Reviewing the vendor's security certifications (e.g., SOC 2, ISO 27001)
Why this is correct
Reviewing a vendor's security certifications, such as SOC 2 or ISO 27001, provides independent assurance that the vendor has implemented and maintains robust security controls. These certifications indicate that an external auditor has verified the effectiveness of the vendor's information security management system (ISMS) against recognized standards. This offers critical insight into the vendor's commitment to security, data protection, and operational resilience, significantly reducing the acquiring organization's due diligence burden.
- ✓
Requesting a Software Bill of Materials (SBOM)
Why this is correct
Requesting a Software Bill of Materials (SBOM) is crucial for understanding the complete software supply chain of the SaaS application. An SBOM provides a comprehensive, machine-readable inventory of all third-party and open-source components used, including their versions and dependencies. This transparency enables the acquiring organization to proactively identify known vulnerabilities (CVEs) within these components, assess potential risks, and understand the vendor's patching cadence, thereby enhancing overall risk management.
- ✓
Assessing the vendor's incident response process
Why this is correct
Assessing the vendor's incident response (IR) process is paramount because it dictates how security incidents affecting the SaaS application and its data will be handled. A well-defined and tested IR plan ensures timely detection, containment, eradication, recovery, and post-incident analysis of security breaches. Understanding this process, including communication protocols and escalation paths, is vital for the acquiring organization to manage its own risk exposure and maintain business continuity during a security event.
- ✗
Requiring employee security training records
Why it's wrong here
While employee security awareness training is a fundamental component of any robust security program, requiring specific training records from a SaaS vendor is less critical than assessing the overall security architecture or operational processes during initial acquisition. This level of granular detail typically falls under ongoing vendor management or audit activities, rather than being a primary indicator of the inherent security of the service itself. Broader certifications and process assessments provide a more comprehensive view of the vendor's security posture.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.