WGU - D487
Study online at https://quizlet.com/_gpcp9p
1. Privacy Compliance Report The _________ report
should provide progress
against privacy require-
ments provided in earli-
er phases. Any outstand-
ing requirement should
be implemented as soon
as possible. It is also
prudent to assess any
changes in laws/regula-
tions to identify (and put
on a roadmap) any new
requirements. A4 D&D
2. Security Testing Reports A findings summary
should be prepared for
each type of security test-
ing: manual code review,
static analysis, dynamic
analysis, penetration test-
ing, and fuzzing. The re-
ports should provide the
type and number of issues
identified and any consis-
tent theme that can be de-
rived from the findings. A4
D&D
3. Remediation Report A ____ report/dashboard
should be prepared and
updated regularly from
this stage. The purpose of
, WGU - D487
Study online at https://quizlet.com/_gpcp9p
this report is to showcase
the security posture and
risk of the product at a
technical level. A4 D&D
4. Security Assessment SDL Phase 1 (A1) = SDLC 1
What are the key activities in the Security Assessment Concept
phase of SDL?
Software security team is
looped in early
Security team hosts a dis-
covery meeting
Software security team
discusses project plan
States what further work
will be done
Privacy Impact Assess-
ment (PIA) plan is created
5. Architecture SDL Phase 2 (A2) = SDLC 2
What are the key activities in the Architecture phase of Planning
SDL?
A2 Policy compliance
analysis
SDL policy assessment
and scoping
Threat modeling & archi-
tecture security analysis
Open-source selection
Privacy information gath-
ering and analysis
6.
, WGU - D487
Study online at https://quizlet.com/_gpcp9p
Design & Development SDL Phase 3 (A3) = SDLC 3
What are the key activities in the Design & Develop- Design & Development
ment phase of SDL?
A3 Policy compliance
analysis
Security test plan compo-
sition
Static analysis updating
Threat modeling analysis
& review
Privacy implementation
assessment
7. Design & Development Cont. SDL Phase 4 (A4) = SDLC 4
What are the key activities in the Design & Develop- Readiness
ment Cont. phase of SDL?
A4 Policy compliance
analysis
Security test case execu-
tion
Static analysis
Fuzz testing
Privacy code review
Privacy validation and re-
mediation
8. Ship SDL Phase 5 (A5) = SDLC 5
What are the key activities in the Ship phase of SDL? Release & Launch
A5 Policy compliance
analysis
Vulnerability scan
Penetration testing
, WGU - D487
Study online at https://quizlet.com/_gpcp9p
Open-source licensing re-
view
Final privacy review
9. What is the purpose of the Product risk profile deliv- To estimate the actual cost
erable in Security Assessment (A1)? of the product.
10. What is the goal of the SDL project outline in Security To map SDL activities to
Assessment (A1)? the development sched-
ule.
11. Why are Applicable laws and regulations important in To obtain formal sign-off
Security Assessment (A1)? from stakeholders on ap-
plicable laws.
12. What is the purpose of the Threat profile in Security To guide SDL activities to
Assessment (A1)? mitigate threats.
13. What is the goal of the Certification requirements de- To list requirements for
liverable in Security Assessment (A1)? product and operations
certifications.
14. Why is maintaining a List of third-party software im- To identify dependence
portant in Security Assessment (A1)? on third-party software.
15. What is the purpose of the Metrics template in Secu- To establish a cadence for
rity Assessment (A1)? regular reporting to exec-
utives.
16. What is the purpose of defining Business require- To establish software
ments in A2 Architecture? requirements, including
Confidentiality, Integrity,
and Availability (CIA).
Study online at https://quizlet.com/_gpcp9p
1. Privacy Compliance Report The _________ report
should provide progress
against privacy require-
ments provided in earli-
er phases. Any outstand-
ing requirement should
be implemented as soon
as possible. It is also
prudent to assess any
changes in laws/regula-
tions to identify (and put
on a roadmap) any new
requirements. A4 D&D
2. Security Testing Reports A findings summary
should be prepared for
each type of security test-
ing: manual code review,
static analysis, dynamic
analysis, penetration test-
ing, and fuzzing. The re-
ports should provide the
type and number of issues
identified and any consis-
tent theme that can be de-
rived from the findings. A4
D&D
3. Remediation Report A ____ report/dashboard
should be prepared and
updated regularly from
this stage. The purpose of
, WGU - D487
Study online at https://quizlet.com/_gpcp9p
this report is to showcase
the security posture and
risk of the product at a
technical level. A4 D&D
4. Security Assessment SDL Phase 1 (A1) = SDLC 1
What are the key activities in the Security Assessment Concept
phase of SDL?
Software security team is
looped in early
Security team hosts a dis-
covery meeting
Software security team
discusses project plan
States what further work
will be done
Privacy Impact Assess-
ment (PIA) plan is created
5. Architecture SDL Phase 2 (A2) = SDLC 2
What are the key activities in the Architecture phase of Planning
SDL?
A2 Policy compliance
analysis
SDL policy assessment
and scoping
Threat modeling & archi-
tecture security analysis
Open-source selection
Privacy information gath-
ering and analysis
6.
, WGU - D487
Study online at https://quizlet.com/_gpcp9p
Design & Development SDL Phase 3 (A3) = SDLC 3
What are the key activities in the Design & Develop- Design & Development
ment phase of SDL?
A3 Policy compliance
analysis
Security test plan compo-
sition
Static analysis updating
Threat modeling analysis
& review
Privacy implementation
assessment
7. Design & Development Cont. SDL Phase 4 (A4) = SDLC 4
What are the key activities in the Design & Develop- Readiness
ment Cont. phase of SDL?
A4 Policy compliance
analysis
Security test case execu-
tion
Static analysis
Fuzz testing
Privacy code review
Privacy validation and re-
mediation
8. Ship SDL Phase 5 (A5) = SDLC 5
What are the key activities in the Ship phase of SDL? Release & Launch
A5 Policy compliance
analysis
Vulnerability scan
Penetration testing
, WGU - D487
Study online at https://quizlet.com/_gpcp9p
Open-source licensing re-
view
Final privacy review
9. What is the purpose of the Product risk profile deliv- To estimate the actual cost
erable in Security Assessment (A1)? of the product.
10. What is the goal of the SDL project outline in Security To map SDL activities to
Assessment (A1)? the development sched-
ule.
11. Why are Applicable laws and regulations important in To obtain formal sign-off
Security Assessment (A1)? from stakeholders on ap-
plicable laws.
12. What is the purpose of the Threat profile in Security To guide SDL activities to
Assessment (A1)? mitigate threats.
13. What is the goal of the Certification requirements de- To list requirements for
liverable in Security Assessment (A1)? product and operations
certifications.
14. Why is maintaining a List of third-party software im- To identify dependence
portant in Security Assessment (A1)? on third-party software.
15. What is the purpose of the Metrics template in Secu- To establish a cadence for
rity Assessment (A1)? regular reporting to exec-
utives.
16. What is the purpose of defining Business require- To establish software
ments in A2 Architecture? requirements, including
Confidentiality, Integrity,
and Availability (CIA).