In agile software development, each sprint ends at a specific point in time and should have some
deliverable. - Answers True
Configuration control is a set of processes and approval stages required to change a configuration item's
attributes and to re-baseline them. - Answers True
The Software Security Framework (SSF) is a component of the Building Security in Maturity Model
(BSIMM) that organizes the 109 BSIMM activities into a framework consisting of 12 practices in four
domains. - Answers True
The Security Development Lifecycle (SDL) is a security assurance process that is focused on software
development. - Answers True
A deliverable is a description of components stored in a database. - Answers False
A Configuration Control Board (CCB) is a person or group of people responsible for making decisions
about changes to the system definition during the course of the development life cycle. - Answers True
Configuration identification is the ability to record and report on the configuration baselines associated
with each configuration item at any moment in time. - Answers False
A schema is any object created as a result of project activities. - Answers False
Configuration auditing is the process of confirming that all system components that should be in a given
baseline are present. - Answers True
The System Process Framework (SPF) is a formal model for the process of creating and modifying
software. - Answers False
Decomposition refers to breaking down a software development project into distinct phases. - Answers
True
The development method an organization uses is more important than attention to security. - Answers
False
Software development is as much an art as it is a science. - Answers True
The most important concept in the Software Development Life Cycle (SDLC) is decomposition, or
breaking down a software development project into distinct phases. - Answers True
Agile development is a method of developing software that is based on small project iterations, or
sprints, instead of long project schedules. - Answers True
One of the main reasons the Building Security in Maturity Model (BSIMM) model is so valuable is that it
reports on what works in the area of secure application development. - Answers True