CompTIA Project+ (PK0-005)Basics of IT and GovernanceMedium

A project is underway to develop a new mobile application that will handle sensitive user data. During the design phase, the security team emphasizes incorporating security measures from the very beginning of the project lifecycle, rather than adding them as an afterthought. Which cybersecurity principle is being applied here?

  1. AZero Trust
  2. BSecurity by Design
  3. CSecurity through Obscurity
  4. DPrinciple of Least Privilege
Show answer & explanation

Correct answer: B. Security by Design

Security by Design (also known as Privacy by Design) advocates for embedding security considerations into the initial design and architecture of a system, rather than patching vulnerabilities later.

Why the other options are wrong

  • A. Zero Trust is a security model that assumes no user or device can be trusted by default, regardless of their location.
  • C. Security through Obscurity relies on hiding vulnerabilities, which is generally not a robust security strategy.
  • D. The Principle of Least Privilege grants minimum necessary access, which is a specific control, not an overarching design philosophy.

Security by Design

Security by Design is a cybersecurity principle that emphasizes the importance of building security into the software and systems from the initial design phase, rather than adding it as an afterthought.

  • Proactive approach to security.
  • Integrates security controls throughout the development lifecycle.
  • Aims to prevent vulnerabilities rather than remediate them.

Memory trick: Design Security: Build it in, don't bolt it on.

More Basics of IT and Governance questions