COMPLETE ACTUAL AND AUTHENTIC EXAM | BRAND NEW!
Privacy Compliance The___report should provide progress against
Report privacy requirements provided
in earlier phases. Any outstanding requirement
should be implemented as soon as possible. It
is also prudent to assess any changes in
laws/regulations to identify
(and put on a roadmap) any new requirements.
A4 D&D
Security Testing Reports A findings summary should be prepared for
each type of security testing: manual code
review, static analysis, dynamic analysis,
penetration testing, and fuzzing.
The reports should provide the type and
number of issues identified and any consistent
theme that can be derived from the
findings. A4 D&D
Remediation Report A__report/dashboard should be prepared and
updated regularly from this
stage. The purpose of this report is to
showcase the security posture and risk of the
product at a technical level. A4 D&D
,Security Assessment SDL Phase 1 (A1) = SDLC 1 Concept
What are the key activities in
the Security Assessment phase Software security team
of SDL? is looped in early
Security team hosts a
discovery meeting
Software security team
discusses project plan
States what further
work will be done
Privacy Impact Assessment (PIA) plan is created
Architecture SDL Phase 2 (A2) = SDLC 2 Planning
What are the key activities in the
Architecture phase of SDL? A2 Policy compliance analysis
SDL policy assessment and scoping
Threat modeling &
architecture security
analysis Open-source
selection
Privacy information gathering and analysis
Design & Development SDL Phase 3 (A3) = SDLC 3 Design &
What are the key activities in the Development
Design & Development phase of
SDL? A3 Policy
compliance
analysis Security
test plan
, composition
Static analysis
updating
Threat modeling
analysis & review
Privacy
implementation
assessment
Design & Development Cont. SDL Phase 4 (A4) = SDLC 4 Readiness
What are the key activities in the
Design & Development Cont. A4 Policy
phase of SDL? compliance
analysis Security
test case
execution Static
analysis
Fuzz testing
Privacy code review
Privacy validation and remediation
Ship SDL Phase 5 (A5) = SDLC 5 Release & Launch
What are the key activities in the
Ship phase of SDL? A5 Policy
compliance
analysis
Vulnerability
scan
Penetration testing
Open-source
licensing review