Courseiva
Software Development SecuritymediumMultiple SelectObjective-mapped

CISSP Software Development Security Practice Question

An organization is planning to acquire a new SaaS application for customer relationship management. Which THREE of the following should be included in the vendor security assessment?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Reviewing the vendor's security certifications (e.g., SOC 2, ISO 27001)

Reviewing the vendor's security certifications (e.g., SOC 2), assessing their incident response process, and requesting a Software Bill of Materials (SBOM) are key steps. License compliance is important but not directly security, and employee training is internal to the vendor but less critical than the others.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Checking license compliance for open source components

    Why it's wrong here

    While important for legal and governance purposes, checking license compliance for open source components primarily addresses intellectual property and contractual obligations, not the direct security posture of the SaaS application. This activity helps mitigate legal risks like copyright infringement or non-compliance with licensing terms, but it does not directly assess the presence of security vulnerabilities or the effectiveness of the vendor's security controls. Therefore, it is not a primary security due diligence activity during SaaS acquisition.

  • Reviewing the vendor's security certifications (e.g., SOC 2, ISO 27001)

    Why this is correct

    Reviewing a vendor's security certifications, such as SOC 2 or ISO 27001, provides independent assurance that the vendor has implemented and maintains robust security controls. These certifications indicate that an external auditor has verified the effectiveness of the vendor's information security management system (ISMS) against recognized standards. This offers critical insight into the vendor's commitment to security, data protection, and operational resilience, significantly reducing the acquiring organization's due diligence burden.

  • Requesting a Software Bill of Materials (SBOM)

    Why this is correct

    Requesting a Software Bill of Materials (SBOM) is crucial for understanding the complete software supply chain of the SaaS application. An SBOM provides a comprehensive, machine-readable inventory of all third-party and open-source components used, including their versions and dependencies. This transparency enables the acquiring organization to proactively identify known vulnerabilities (CVEs) within these components, assess potential risks, and understand the vendor's patching cadence, thereby enhancing overall risk management.

  • Assessing the vendor's incident response process

    Why this is correct

    Assessing the vendor's incident response (IR) process is paramount because it dictates how security incidents affecting the SaaS application and its data will be handled. A well-defined and tested IR plan ensures timely detection, containment, eradication, recovery, and post-incident analysis of security breaches. Understanding this process, including communication protocols and escalation paths, is vital for the acquiring organization to manage its own risk exposure and maintain business continuity during a security event.

  • Requiring employee security training records

    Why it's wrong here

    While employee security awareness training is a fundamental component of any robust security program, requiring specific training records from a SaaS vendor is less critical than assessing the overall security architecture or operational processes during initial acquisition. This level of granular detail typically falls under ongoing vendor management or audit activities, rather than being a primary indicator of the inherent security of the service itself. Broader certifications and process assessments provide a more comprehensive view of the vendor's security posture.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.