Which privacy impact statement requirement type defines how personal information will be protected when
authorized or independent external entities are involved?
The security team has received notice of an insecure direct object reference vulnerability in a third-party
component library that could result in remote code execution. The component library was replaced and is no
longer being used within the application.
How should the organization remediate this vulnerability?
The security team is reviewing all noncommercial software libraries used in the new product to ensure they
are being used according to the legal specifications defined by the authors.
What activity of the Ship SDL phase is being performed?
The security team is reviewing all noncommercial software libraries used in the new product to ensure they
are being used according to the legal specifications defined by the authors.
What activity of the Ship SDL phase is being performed?