SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationHard

An organization is developing a new critical application and is concerned about the security of its supply chain, particularly the third-party components and libraries used. To ensure these components do not introduce known vulnerabilities, which of the following practices should be integrated into the development lifecycle?

  1. ARegular penetration testing of the final application.
  2. BConducting annual security awareness training for developers.
  3. CImplementing a robust bug bounty program.
  4. DUtilizing Software Composition Analysis (SCA) tools.
Show answer & explanation

Correct answer: D. Utilizing Software Composition Analysis (SCA) tools.

Software Composition Analysis (SCA) tools are specifically designed to identify open-source and third-party components within an application and check them against databases of known vulnerabilities and licensing issues. This directly addresses the concern about third-party components introducing vulnerabilities.

Why the other options are wrong

  • A. Penetration testing identifies vulnerabilities in the assembled application but may not effectively pinpoint vulnerabilities within specific third-party components or their licenses.
  • B. Security awareness training is important for developers but doesn't provide an automated, systematic way to scan third-party libraries for known vulnerabilities.
  • C. A bug bounty program incentivizes external researchers to find vulnerabilities but is reactive and general, not specifically focused on the proactive identification of issues in third-party components during development.

Software Composition Analysis (SCA)

Software Composition Analysis (SCA) is a process and set of tools used to automate the identification of open-source and third-party components in a codebase, along with their associated licenses, known vulnerabilities, and security risks.

  • Identifies open-source and commercial third-party components.
  • Scans for known vulnerabilities (CVEs) in these components.
  • Helps manage licensing compliance.
  • Integrated into CI/CD pipelines for continuous monitoring.

Memory trick: Secure your code's ingredients before you bake the cake.

More Security Operations and Administration questions