CompTIA Project+ (PK0-005)Basics of IT and GovernanceMedium
A project is developing a new online banking application. During the design phase, the project manager emphasizes the importance of embedding security controls and considerations from the initial stages of development, rather than adding them as an afterthought. This approach is known as:
- ASecurity by design
- BCompliance-driven security
- CReactive security
- DSecurity through obscurity
Show answer & explanationAnswer & explanation
Correct answer: A. Security by design
Security by Design is a development principle that ensures security considerations are integrated into all phases of the software development lifecycle, starting from the very beginning, rather than being bolted on later.
Why the other options are wrong
- B. While compliance is a driver, 'security by design' is the methodology for embedding security proactively.
- C. Reactive security addresses issues after they occur, contrary to the proactive approach described.
- D. Security through obscurity relies on hiding vulnerabilities, which is not a robust security strategy.
Security by Design
An approach to software and system development that involves building security into the architecture and design from the very beginning, proactively addressing potential vulnerabilities rather than patching them later.
- Integrates security throughout the SDLC.
- Reduces costs and risks in the long run.
- Focuses on preventing vulnerabilities, not just detecting them.
Memory trick: Design security, don't just patch it on.