Valid CISSP Dumps shared by EduDump.com for Helping Passing CISSP Exam! EduDump.com now offer the newest CISSP exam dumps, the EduDump.com CISSP exam questions have been updated and answers have been corrected get the newest EduDump.com CISSP dumps with Test Engine here:
A security professional in an enterprise organization is evaluating a software product for acquisition. During the contracting phase of the acquisition, the security professional learned that the software product has certain security flaws and as a result does not meet the security requirements. Which of the following should the security professional do in response to the situation?
Correct Answer: D
When a software product has known security flaws but is still under consideration, the most practical and professional response is to negotiate contract terms that mitigate the associated risks. This might include: Requiring the vendor to fix the flaws within a certain timeframe Including service-level agreements (SLAs) for security updates Adding penalties or remediation clauses Requiring integration with compensating controls