Which of the following addresses requirements of security assessments during software acquisition?
Correct Answer: D
The software assurance policy is the best option that addresses the requirements of security assessments during software acquisition. The software assurance policy is a policy that defines the standards, guidelines, and procedures for ensuring the security, quality, and reliability of the software acquired by the organization. The software assurance policy should include the security requirements and specifications for the software, the security evaluation criteria and methods for the software, the roles and responsibilities of the stakeholders involved in the software acquisition, and the security monitoring and reporting mechanisms for the software.
The software assurance policy should also align with the organization's security policies and objectives, and comply with the relevant laws and regulations . References: [CISSP CBK, Fifth Edition, Chapter 3, page 211];
[100 CISSP Questions, Answers and Explanations, Question 10].