ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationMedium

An IS auditor is evaluating the controls over software development for a critical in-house application. The development team frequently uses open-source libraries. Which of the following is the MOST important control to ensure the ongoing security of the application?

  1. AMandatory security awareness training for all developers.
  2. BImplementation of a software composition analysis (SCA) tool.
  3. CRegular vulnerability scanning of the application code.
  4. DAdherence to secure coding standards for all custom-developed modules.
Show answer & explanation

Correct answer: B. Implementation of a software composition analysis (SCA) tool.

Given the frequent use of open-source libraries, a Software Composition Analysis (SCA) tool is specifically designed to identify known vulnerabilities in these third-party components, which often account for a significant portion of an application's codebase and are a common attack vector.

Why the other options are wrong

  • A. Training is foundational but doesn't directly address the technical challenge of managing open-source component vulnerabilities.
  • C. Vulnerability scanning is important but may not deeply analyze known vulnerabilities within specific versions of open-source libraries.
  • D. Secure coding standards apply to custom code, but not directly to vulnerabilities inherent in external libraries.

Software Composition Analysis (SCA)

A process and toolset used to identify and manage open-source and third-party components within a codebase, detecting known vulnerabilities and licensing issues.

  • Addresses risks from external libraries.
  • Identifies known vulnerabilities (CVEs).
  • Helps manage licensing compliance.

Memory trick: Open-source, open-eyes for SCA!

More Domain 3: Information Systems Acquisition, Development and Implementation questions