The correct answer is C because the question focuses on helping web developers understand the growing severity of web application security risks. A tailored security awareness training program can address the specific threats, attack patterns, vulnerabilities, coding mistakes, business impacts, and regulatory consequences relevant to web development. Tailored training is more effective than generic awareness because it connects security risks directly to the developers’ roles and responsibilities. Incorporating security requirements into job descriptions may establish accountability, but it does not ensure understanding of current and emerging risks. Integrating security early in the development life cycle is a strong practice, but it is more about process integration than developer understanding. Standardizing secure development practices is important for consistency, but developers must first understand why those practices matter and how risks affect the organization. CISM program development principles emphasize role-based awareness and training to support effective security behavior. Therefore, customized awareness training is the best way to improve developers’ understanding of web application risk severity.
[Reference: CISM Information Security Program Development and Management; role-based security awareness, secure development, web application risk, and training principles., , ]
Submit