Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard
A software development team needs to ensure that only specific versions of libraries and approved components are used in their applications to prevent known vulnerabilities from being introduced. Which compliance concept is this primarily related to?
- ACode Compliance
- BData Minimization
- CPrivacy by Design
- DSupply Chain Security
Show answer & explanationAnswer & explanation
Correct answer: D. Supply Chain Security
Ensuring the integrity and security of third-party libraries and components falls under Supply Chain Security, as it addresses risks introduced by external elements used in the software development process.
Why the other options are wrong
- A. Code Compliance generally refers to adherence to coding standards or security best practices within the *organization's own code*, not specifically external libraries.
- B. Data Minimization is about collecting only necessary data, not managing code components.
- C. Privacy by Design integrates privacy considerations throughout the entire development lifecycle, which is broader than just library versions.
Supply Chain Security
The process of identifying, assessing, and mitigating risks associated with third-party products, services, and components used in an organization's systems or software.
- Addresses vulnerabilities introduced by external dependencies.
- Crucial for software development using open-source or commercial libraries.
- Includes vetting vendors and managing component versions.
Memory trick: Supply Chain: External parts are part of the puzzle