Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard
A software development team needs to ensure that only specific versions of libraries and approved software components are used in their applications to reduce security risks. They also want to enforce coding standards and security best practices during the development pipeline. Which compliance concept are they focusing on?
- AInformation Protection
- BCode Compliance
- CSupply Chain Security
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: B. Code Compliance
Code Compliance refers to ensuring that software code adheres to predefined standards, security policies, and regulatory requirements, including the use of approved components and secure coding practices throughout the development lifecycle.
Why the other options are wrong
- A. Information Protection deals with classifying, labeling, and encrypting data, not the code itself.
- C. Supply Chain Security broadly covers risks from third-party components, but 'Code Compliance' is more specific to the internal development and use of those components within the code.
- D. DLP focuses on preventing sensitive data from leaving the organization, not on code quality or components.
Code Compliance
The practice of ensuring that software code adheres to predefined organizational standards, security policies, and regulatory requirements throughout its development lifecycle.
- Encompasses secure coding practices and architectural patterns.
- Includes managing dependencies and approved component usage.
- Aims to reduce vulnerabilities and ensure maintainability.
Memory trick: Code Compliance: The rules for writing good, safe code.