Software Development Security Question #44

Your C-level executives have a low risk appetite and prioritize stability. How should you approach a Maturity Model (MM) report for governance and risk?

A. Targets will be gradually increased over time, while criteria continue to reflect the current state.
B. The targets will be set modestly, with model domains, levels, and criteria reflecting the company's current capabilities and risk posture.
C. The model domains will be narrowed as much as possible, aiming to achieve high levels of maturity for a limited number of areas.
D. The maturity model’s criteria will be set modestly with no plans for significant improvement.
Domain Concept: Software Development Security

This scenario evaluates management-level decision making in Software Development Security. In CISSP exam scenarios, evaluate answers through executive governance, risk assessment, life safety, and due diligence before implementing technical controls.

💡 View the Answer & Detailed Explanation

The correct answer to this scenario-based question requires an understanding of the CISSP Managerial Mindset. Register to view our in-depth explanation and access 1100+ adaptive questions completely free.

Fuel the Mission ☕

Keep the vault updated and the servers running.

$
Secure Payment via PayPal

Verified Excellence

Spread the Word

If you like us, share us with your peers.

Scroll to Top