CompTIA Project+ (PK0-005)Basics of IT and GovernanceHard
A project is initiating the development of a new mobile banking application. Given that the application will handle sensitive financial transactions and personal user data, which security consideration should be integrated from the earliest phases of the project lifecycle?
- AConducting penetration testing only just before the application's launch.
- BOutsourcing all security audits to the lowest-bid third-party vendor.
- CImplementing a 'Security by Design' approach throughout development.
- DRelying solely on end-user antivirus software for protection.
Show answer & explanationAnswer & explanation
Correct answer: C. Implementing a 'Security by Design' approach throughout development.
'Security by Design' (also known as 'Privacy by Design' when focusing on data privacy) advocates for integrating security considerations into every phase of the project lifecycle, starting from initial design. For a mobile banking app handling sensitive financial data, this proactive approach is critical to building a secure foundation rather than attempting to bolt on security later.
Why the other options are wrong
- A. Penetration testing is important, but doing it only at the end is a reactive approach and too late to fix fundamental design flaws easily.
- B. Outsourcing audits is not inherently bad, but doing so to the 'lowest-bid' and not integrating security earlier indicates a reactive, potentially low-quality approach.
- D. Relying solely on end-user software is insufficient for securing a banking application's backend and data handling.
Security by Design
An approach to software and system development that involves integrating security considerations and controls into every phase of the development lifecycle, from initial design to deployment and maintenance.
- Proactive rather than reactive security.
- Aims to prevent vulnerabilities rather than fix them after they appear.
- More cost-effective than patching security flaws post-deployment.
Memory trick: Secure Dev: Design, Build, Test, Deploy, Monitor.