A CIO asks whether the municipality’s custom-development practices are immature or advancing. Which approach best answers that question?
Select an answer to reveal the explanation.
Short Explanation
“Are we grown-ups at secure coding?” isn’t a gut feel. Use a maturity model—CMM/SAMM-style—to score practices level by level instead of counting commits or hoping nothing blew up.
Full Explanation
Software security maturity models (for example CMM-oriented or OWASP SAMM-class approaches) provide structured levels and practices to evaluate how consistently an organization performs secure development activities. Volume metrics, blogs, or recent uptime alone do not measure security process maturity for municipal development shops. Assessments guide roadmaps for training, tooling, and governance. CISSP expects familiarity with using such models to improve SDLC security over time.