A Chief Information Security Officer (CISO) has developed information security policies that relate to the software development methodology. Which of the following would the CISO most likely include in the organization’s documentation?
Choose an answer
Tap an option to check your answer.
Correct answer: Peer review requirements.
Why this is the answer
Peer review requirements are a crucial part of secure software development. They ensure that code is reviewed by other developers for vulnerabilities, adherence to coding standards, and logical errors before deployment, directly contributing to the security and quality of the software. Multifactor authentication (MFA) is an access control mechanism, not a software development policy. Branch protection tests are a specific type of security testing within a version control system, while important, "peer review requirements" encompass a broader and more fundamental policy for secure development. Secrets management configurations deal with how sensitive information (like API keys) is handled, which is a technical implementation detail rather than a policy governing the development process itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed