Question 1 of 30
When procuring a Commercial Off-The-Shelf (COTS) software solution for a critical financial reporting system, a regulatory compliance audit has highlighted potential data integrity vulnerabilities. The organization cannot dictate the internal development practices of the COTS vendor. According to the principles outlined in ISO/IEC 25051:2014 for specifying quality requirements for COTS products, what is the most appropriate strategy to address these identified data integrity concerns?
Define specific, measurable, and verifiable data validation rules and error handling mechanisms that the COTS software must exhibit during end-to-end transaction processing tests, supported by vendor-provided documentation on data consistency features.
Mandate that the COTS vendor adhere to a specific secure coding standard and provide access to their source code for independent security code reviews.
Require the COTS vendor to implement a comprehensive internal quality assurance program that includes unit testing for all data manipulation modules.
Specify that the COTS software must be developed using a particular programming language known for its inherent data security features.

Preparing for ISO/IEC 25051:2014 - COTS Software Product Quality Requirements Professional? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free