Q: What is a viable alternative to hiring a human software security expert to prevent requirements-level threats?
-
A
Improved documentation
-
B
Comprehensive security requirements checklist
-
C
More time spent on requirements elicitation
-
D
Adding additional checkpoints
B
Answer:
B
Explanation:
A comprehensive security requirements checklist is a viable alternative to hiring a human software security expert to prevent requirements-level threats. This checklist provides a structured approach to identifying and addressing security concerns at the requirements stage, ensuring that security considerations are incorporated early in the software development lifecycle. It can help ensure that the software meets security standards and mitigates common risks without needing a dedicated security expert for each project. Improved documentation, additional checkpoints, and spending more time on requirements elicitation may also contribute to better security practices but may not be as effective at specifically addressing requirements-level threats.
Related Topic:
Share Above MCQ