QuestionQ4

Governance, Risk, and Compliance

A security architect is analyzing an old application that is not covered for maintenance anymore because the software company is no longer in business. Which of the following techniques should have been implemented to prevent these types of risks?

Explanation

A source code escrow places the application's source code with a neutral third party that releases it to the customer if the vendor goes out of business, stops support, or otherwise fails to meet contractual maintenance obligations, which is exactly the scenario described. Code reviews, supply chain visibility, and software audits improve quality and risk awareness at the time they are performed but do nothing to guarantee continued access to or maintainability of the code once the vendor disappears.

Community Discussion

No comments yet. Be the first to start the discussion!