The correct answer is C because emerging risk should be addressed as early as possible in the system development life cycle, beginning with the planning phase. During planning, the organization defines business objectives, scope, requirements, stakeholders, expected benefits, technology approach, and initial risk considerations. Addressing risk early allows security requirements, compliance obligations, privacy needs, architecture expectations, and control considerations to be included before major design and implementation decisions are made. If risk is first addressed during design, implementation, or testing, the organization may face higher remediation costs, delays, or architectural limitations. Testing can identify whether controls are working, but it is too late to be the first point for addressing emerging risk. CISM emphasizes integrating security and risk management into business processes and system life cycle activities from the beginning. Early risk identification supports better decision-making, cost-effective control design, and alignment with business objectives. Therefore, the first phase should be planning.
[Reference: CISM Information Risk Management; system development life cycle, early risk identification, security requirements, and risk-based planning principles., , ]
Submit