Isaca Certified in Risk and Information Systems Control CRISC Question # 230 Topic 24 Discussion
CRISC Exam Topic 24 Question 230 Discussion:
Question #: 230
Topic #: 24
During which phase of the system development life cycle (SDLC) should information security requirements for the implementation of a new IT system be defined?
Information security requirements should be defined during theInitiationphase of the SDLC. This ensures that security is integrated into the design from the beginning, minimizing vulnerabilities and aligning security measures with business requirements. Early identification of security needs reduces rework and costs associated with later stages.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit