Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security

A Hyderabad company outsources development of a customer-data system to a vendor. The contract requires source code review, security testing before go-live, and a change-control process for later modifications. Which statement best reflects how these contract terms map to SDLC and the duty to protect personal data under Indian law?

The terms support reasonable security practices across development and maintenance, and the company holding the data stays accountable despite outsourcing. Code review, security testing and change control build safeguards into the SDLC, so liability cannot be shifted entirely to the vendor.

  1. AThey are irrelevant, since liability for data protection lies only with the vendor
  2. BThey are needed only for software exported outside India
  3. CThey support implementing reasonable security practices across development and maintenance, which the data-owning company remains accountable forCorrect
  4. DThey replace the need for any testing by the company itself

Explanation

Under Indian IT law and data protection principles, the entity holding personal data must maintain reasonable security safeguards, and outsourcing does not remove that accountability. Code review, pre-release security testing and change control embed safeguards into development and maintenance. Pushing all liability to the vendor or exempting domestic software is incorrect.

Did you get it right without looking?

One question tells you little. A timed set on Softwares and Software Security shows your real accuracy, how long you take and where you lose marks.

More Softwares and Software Security questions