ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityEasy
A software development team is preparing for a new release. During the final testing phase, several critical vulnerabilities are identified in third-party libraries used within the application. The project manager is pushing for an immediate release due to business pressures. Which of the following is the MOST appropriate action for the security team to recommend?
- AAccept the risk, document the vulnerabilities, and schedule patches for a future release.
- BDelay the release until all identified critical vulnerabilities in third-party libraries are patched or mitigated.
- CIsolate the vulnerable components and disable functionalities that rely on them for the initial release.
- DProceed with the release but implement a web application firewall (WAF) to mitigate identified risks.
Show answer & explanationAnswer & explanation
Correct answer: B. Delay the release until all identified critical vulnerabilities in third-party libraries are patched or mitigated.
Ignoring critical vulnerabilities, especially in third-party components which might have wider impact, is a significant security risk. Delaying the release to address these issues is the most responsible and secure action. Implementing a WAF might help but does not fix the underlying vulnerability.
Why the other options are wrong
- A. Accepting critical risks without immediate mitigation is generally poor security practice and can lead to severe consequences.
- C. Isolating components might not be feasible or could impact core functionality, and disabling features for critical vulnerabilities is a last resort, not a primary solution.
- D. A WAF provides a layer of defense but does not eliminate the underlying software vulnerabilities, leaving the application susceptible.
Vulnerability Management
The process of identifying, evaluating, treating, and reporting on security vulnerabilities in systems and software.
- Involves continuous scanning and assessment.
- Prioritizes vulnerabilities based on risk.
- Includes patching, configuration changes, or other mitigations.
Memory trick: Critical bugs demand immediate action, not just a patch-up plan.