CompTIA Project+ (PK0-005)Basics of IT and GovernanceMedium
A project involves developing a new online banking application. During the design phase, the project team must incorporate security measures from the very beginning, rather than adding them as an afterthought. This approach aims to minimize vulnerabilities and reduce the cost of fixing security flaws later. Which security principle is being applied here?
- ASecurity by Design
- BSeparation of Duties
- CLeast Privilege
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: A. Security by Design
Security by Design (or Privacy by Design) is the principle of integrating security considerations into the entire software development lifecycle from the initial design phase, which aligns with the goal of minimizing vulnerabilities and reducing future costs.
Why the other options are wrong
- B. Separation of Duties divides critical tasks among different individuals to prevent fraud or error, a control related to human processes, not software design methodology.
- C. Least Privilege grants users/systems only the minimum access necessary for their tasks, which is a specific security control, not a development approach.
- D. Defense in Depth involves using multiple layers of security controls, which is a strategy for implementation, not the overarching design principle described.
Security by Design
A principle that advocates for the integration of security considerations and controls into every stage of the system development lifecycle, starting from the initial design phase.
- Proactive approach to security.
- Reduces vulnerabilities and remediation costs.
- Ensures security is a core component, not an add-on.
Memory trick: Build security in, don't bolt it on later.