Thread Content
9.14--In the CAESARII version, those who answer the daily questions correctly receive 10 units of wealth, while those who get them wrong receive 3 units. The principle of software security assurance lies in applying risk management throughout the entire lifecycle of the software, in order to achieve the best possible level of protection within limited resources. This helps to avoid direct losses resulting from insufficient safeguards; at the same time, it is also necessary to be aware of the indirect losses that can arise from excessive safeguards. Among the following software security development strategies, the one that does not conform to the principles of software security assurance is: A. Conducting comprehensive security testing on the software before it is released, including source code analysis, fuzz testing, and penetration testing; software that has not undergone such testing is not allowed to be deployed. B. Inviting software security experts to review the software architecture design during the security design phase, in order to identify any security weaknesses in the architecture as early as possible. C. Ensuring that software developers receive security training, so that they understand the basic principles and methods of secure coding, thereby enabling them to write secure code. D. Taking into account the costs related to software security at the stage of project initiation, by allocating funds for security testing and reviews, to ensure that these security-related expenses are covered&
The concept of software security assurance is to apply risk management principles throughout the entire lifecycle of software, in order to achieve the best possible level of security protection with limited resources. This approach helps to avoid direct losses resulting from inadequate safeguards, while also taking into account the indirect costs associated with excessive safeguards. Among the following software security development strategies, the one that does not conform to the principles of software security assurance is: DA. Conducting comprehensive security testing on the software before it is released, including source code analysis, fuzz testing, and penetration testing; software that has not undergone such testing is not allowed to be put into use. B. During the software’s security design phase, inviting experts in software security development to review the software architecture design in order to identify any security weaknesses as early as possible. C. Ensuring that software developers receive security training, so that they understand the basic principles and methods of secure coding, thereby enabling them to write secure code. D. Taking into account the costs related to software security at the stage of project initiation, by allocating funds for security testing and security reviews, thus ensuring that the necessary resources for security are provided&