The planning department wants to buy a commercial off-the-shelf permitting package. What should security do before purchase?
Select an answer to reveal the explanation.
Short Explanation
Buying a shiny permitting package is still adopting someone else's risk. Do the security homework before the purchase order—auth, data handling, patch cadence, integrations. COTS is not "secure by brochure."
Full Explanation
Acquiring COTS software requires evaluating security impact: authentication and authorization models, data protection, vulnerability management, integration surfaces, and residual risk to municipal operations. Purchase decisions should incorporate that assessment rather than assuming commercial branding equals assurance. Domain 8 explicitly covers security implications of acquired software.