Security features are typically considerednon-functional requirements (NFRs), which should be captured in theproduct backlogand prioritized accordingly. As per thePMI Agile Practice Guide (Section 5.1: Product Backlog)andMike Griffiths’ PMI-ACP Exam Prep Book (Chapter 6: Value-Driven Delivery), any requested functionality—whether business- or system-level—must beclearly defined as a backlog itemso the team can plan for it.
Option Ais correct: security requirements should beadded to the backlog and prioritizedlike other features.
Option Bmay come later if implementation is unclear, but first, the work must be defined and logged.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit