ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityMedium

A software vendor is evaluating third-party components and libraries for inclusion in their new product. They are concerned about potential intellectual property (IP) infringement and hidden vulnerabilities. Which of the following assessments would be most effective in addressing both of these concerns?

  1. ABlack-box penetration testing of the final application.
  2. BManual code review by an independent security expert.
  3. CSoftware Composition Analysis (SCA) of all third-party components.
  4. DDynamic Application Security Testing (DAST) on the integrated product.
Show answer & explanation

Correct answer: C. Software Composition Analysis (SCA) of all third-party components.

Software Composition Analysis (SCA) specifically identifies open-source and third-party components within an application, analyzes their licenses for IP compliance, and checks for known vulnerabilities associated with those components, directly addressing both concerns.

Why the other options are wrong

  • A. Black-box penetration testing focuses on discovering vulnerabilities from an attacker's perspective on the deployed application, not on IP compliance or component-level known vulnerabilities.
  • B. Manual code review is effective but can be very time-consuming and might miss broader IP or known vulnerability issues across a large number of third-party components.
  • D. DAST tests the running application for vulnerabilities but doesn't specifically analyze component licenses or directly identify vulnerabilities within specific third-party components.

Software Composition Analysis (SCA)

A tool or process that identifies open-source and third-party components in an application, along with their licenses, known vulnerabilities, and potential security risks.

  • Manages open-source software (OSS) risks
  • Identifies licensing compliance issues
  • Detects known vulnerabilities in OSS components

Memory trick: Component analysis, licenses and flaws, SCA knows all the legal laws.

More Software Development Security questions