SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationHard
An organization is developing a new critical application and is concerned about the security of its supply chain, particularly the third-party components and libraries used. To ensure these components do not introduce known vulnerabilities, which of the following practices should be integrated into the development lifecycle?
- ARegular penetration testing of the final application.
- BConducting annual security awareness training for developers.
- CImplementing a robust bug bounty program.
- DUtilizing Software Composition Analysis (SCA) tools.
Show answer & explanationAnswer & explanation
Correct answer: D. Utilizing Software Composition Analysis (SCA) tools.
Software Composition Analysis (SCA) tools are specifically designed to identify open-source and third-party components within an application and check them against databases of known vulnerabilities and licensing issues. This directly addresses the concern about third-party components introducing vulnerabilities.
Why the other options are wrong
- A. Penetration testing identifies vulnerabilities in the assembled application but may not effectively pinpoint vulnerabilities within specific third-party components or their licenses.
- B. Security awareness training is important for developers but doesn't provide an automated, systematic way to scan third-party libraries for known vulnerabilities.
- C. A bug bounty program incentivizes external researchers to find vulnerabilities but is reactive and general, not specifically focused on the proactive identification of issues in third-party components during development.
Software Composition Analysis (SCA)
Software Composition Analysis (SCA) is a process and set of tools used to automate the identification of open-source and third-party components in a codebase, along with their associated licenses, known vulnerabilities, and security risks.
- Identifies open-source and commercial third-party components.
- Scans for known vulnerabilities (CVEs) in these components.
- Helps manage licensing compliance.
- Integrated into CI/CD pipelines for continuous monitoring.
Memory trick: Secure your code's ingredients before you bake the cake.