ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationMedium
An IS auditor is evaluating the controls over software development for a critical in-house application. The development team frequently uses open-source libraries. Which of the following is the MOST important control to ensure the ongoing security of the application?
- AMandatory security awareness training for all developers.
- BImplementation of a software composition analysis (SCA) tool.
- CRegular vulnerability scanning of the application code.
- DAdherence to secure coding standards for all custom-developed modules.
Show answer & explanationAnswer & explanation
Correct answer: B. Implementation of a software composition analysis (SCA) tool.
Given the frequent use of open-source libraries, a Software Composition Analysis (SCA) tool is specifically designed to identify known vulnerabilities in these third-party components, which often account for a significant portion of an application's codebase and are a common attack vector.
Why the other options are wrong
- A. Training is foundational but doesn't directly address the technical challenge of managing open-source component vulnerabilities.
- C. Vulnerability scanning is important but may not deeply analyze known vulnerabilities within specific versions of open-source libraries.
- D. Secure coding standards apply to custom code, but not directly to vulnerabilities inherent in external libraries.
Software Composition Analysis (SCA)
A process and toolset used to identify and manage open-source and third-party components within a codebase, detecting known vulnerabilities and licensing issues.
- Addresses risks from external libraries.
- Identifies known vulnerabilities (CVEs).
- Helps manage licensing compliance.
Memory trick: Open-source, open-eyes for SCA!