Which statement is NOT aligned with Req 6.5 for software development practices?

Boost your readiness for the PCI DSS Requirements Exam with engaging flashcards and comprehensive multiple choice questions. Each comes with hints and explanations to maximize your understanding!

Multiple Choice

Which statement is NOT aligned with Req 6.5 for software development practices?

Explanation:
Req 6.5 expects that software developed internally follows secure coding practices. It supports establishing secure coding guidelines as a baseline, training developers in secure coding techniques, and building applications in line with those secure guidelines. Training helps developers recognize and prevent common vulnerabilities; a secure coding baseline ensures everyone uses the same secure standards; and building software based on those guidelines translates security into the actual product. The statement that is not aligned is developing applications based on insecure coding guidelines. Using insecure guidelines would propagate vulnerabilities through the software, directly contradicting the purpose of secure development practices under this requirement. The other statements—training developers in secure techniques, establishing secure coding guidelines as a baseline, and developing applications according to those secure guidelines—are all consistent with Req 6.5.

Req 6.5 expects that software developed internally follows secure coding practices. It supports establishing secure coding guidelines as a baseline, training developers in secure coding techniques, and building applications in line with those secure guidelines. Training helps developers recognize and prevent common vulnerabilities; a secure coding baseline ensures everyone uses the same secure standards; and building software based on those guidelines translates security into the actual product.

The statement that is not aligned is developing applications based on insecure coding guidelines. Using insecure guidelines would propagate vulnerabilities through the software, directly contradicting the purpose of secure development practices under this requirement. The other statements—training developers in secure techniques, establishing secure coding guidelines as a baseline, and developing applications according to those secure guidelines—are all consistent with Req 6.5.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy