CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security
A Hyderabad company outsources development of a customer-data system to a vendor. The contract requires source code review, security testing before go-live, and a change-control process for later modifications. Which statement best reflects how these contract terms map to SDLC and the duty to protect personal data under Indian law?
The terms support reasonable security practices across development and maintenance, and the company holding the data stays accountable despite outsourcing. Code review, security testing and change control build safeguards into the SDLC, so liability cannot be shifted entirely to the vendor.
- AThey are irrelevant, since liability for data protection lies only with the vendor
- BThey are needed only for software exported outside India
- CThey support implementing reasonable security practices across development and maintenance, which the data-owning company remains accountable forCorrect
- DThey replace the need for any testing by the company itself
Explanation
Under Indian IT law and data protection principles, the entity holding personal data must maintain reasonable security safeguards, and outsourcing does not remove that accountability. Code review, pre-release security testing and change control embed safeguards into development and maintenance. Pushing all liability to the vendor or exempting domestic software is incorrect.
Did you get it right without looking?
One question tells you little. A timed set on Softwares and Software Security shows your real accuracy, how long you take and where you lose marks.
More Softwares and Software Security questions
- A program copies more data into a fixed-size memory area than it can hold, overwriting adjacent memory and allowing an attacker to run injec…
- Under the Information Technology Act, 2000, a software developer in Pune deliberately inserts a hidden routine into a client's accounting so…
- Meridian Pay's team follows a secure software development life cycle. During the design phase, it systematically identifies assets, entry po…
- A company deposits the source code of bespoke software with a neutral third party, to be released to the customer if the vendor becomes inso…
- A developer in Hyderabad releases a tool under GPL. A Chennai firm modifies it, bundles it into a product and distributes the product to cus…
- Zenith Analytics develops a data-cleaning algorithm in India and wants protection for the software. Which statement reflects the position un…