Isaca Certified in Risk and Information Systems Control CRISC Question # 257 Topic 26 Discussion
CRISC Exam Topic 26 Question 257 Discussion:
Question #: 257
Topic #: 26
During which phase of the system development life cycle (SDLC) should information security requirements for the implementation of a new IT system be defined?
Information security requirements should be defined during theInitiationphase of the SDLC. This ensures that security is integrated into the design from the beginning, minimizing vulnerabilities and aligning security measures with business requirements. Early identification of security needs reduces rework and costs associated with later stages.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit