問題文
A team lists four inputs to the security requirements of a new patient portal: a national health privacy statute, an internal secure coding guideline, a vendor product hardening guide, and a team review checklist entry. The architect is asked which of these the team cannot tailor or waive on its own authority. Which input is that?
選択肢
- The team must treat the internal secure coding guideline as the authoritative input.
- The team must treat the team review checklist entry as the authoritative input.
- The team must treat the national health privacy statute as the authoritative input.
- The team must treat the vendor product hardening guide as the authoritative input.