1
COMPUTER SCIENCE SOFTWARE ENGINEERING D487
SECURE SW DESIGN
Which post-release support activity PRSA1: External vulnerability disclosure response
defines the process to communicate,
identify, and alleviate security
threats?
What are two core practice areas of Governance, Construction
the OWASP Security Assurance
Maturity Model (OpenSAMM)?
Which practice in the Ship (A5) phase Vulnerability scan
of the security
development cycle uses tools to identify
weaknesses in the
product?
Which post-release support activity Security architectural reviews
should be completed when
companies are joining together?
Which of the Ship (A5) Analyze activities and standards
deliverables of the security
development cycle are performed
during the A5 policy compliance
analysis?
Which of the Ship (A5) white-box security test
deliverables of the security
development cycle are performed
during the code- assisted penetration
testing?
Which of the Ship (A5) license compliance
deliverables of the security
development cycle are performed
during the open- source licensing
review?
Which of the Ship (A5) Release and ship
deliverables of the security
development cycle are performed
during the final security review?
, 2
How can you establish your own SDL to iterative development
build security into a
process appropriate for your
organization's needs based on agile?
How can you establish your own SDL to continuous integration and continuous deployments
build security into a
process appropriate for your
organization's needs based on
devops?
COMPUTER SCIENCE SOFTWARE ENGINEERING D487
SECURE SW DESIGN
Which post-release support activity PRSA1: External vulnerability disclosure response
defines the process to communicate,
identify, and alleviate security
threats?
What are two core practice areas of Governance, Construction
the OWASP Security Assurance
Maturity Model (OpenSAMM)?
Which practice in the Ship (A5) phase Vulnerability scan
of the security
development cycle uses tools to identify
weaknesses in the
product?
Which post-release support activity Security architectural reviews
should be completed when
companies are joining together?
Which of the Ship (A5) Analyze activities and standards
deliverables of the security
development cycle are performed
during the A5 policy compliance
analysis?
Which of the Ship (A5) white-box security test
deliverables of the security
development cycle are performed
during the code- assisted penetration
testing?
Which of the Ship (A5) license compliance
deliverables of the security
development cycle are performed
during the open- source licensing
review?
Which of the Ship (A5) Release and ship
deliverables of the security
development cycle are performed
during the final security review?
, 2
How can you establish your own SDL to iterative development
build security into a
process appropriate for your
organization's needs based on agile?
How can you establish your own SDL to continuous integration and continuous deployments
build security into a
process appropriate for your
organization's needs based on
devops?