CompTIA Project+ (PK0-005)Basics of IT and GovernanceMedium
A project involves developing a new mobile application that will process sensitive user biometric data. The project manager needs to ensure that the application's design inherently incorporates security measures from the outset, rather than adding them as an afterthought. Which cybersecurity principle is the project manager prioritizing?
- ASecurity by Design
- BDefense in Depth
- CSeparation of Duties
- DLeast Privilege
Show answer & explanationAnswer & explanation
Correct answer: A. Security by Design
Security by Design (or Privacy by Design) is a principle that advocates for embedding security and privacy considerations into the architecture and operations of IT systems and business practices from the very beginning of the project lifecycle.
Why the other options are wrong
- B. Defense in Depth involves multiple layers of security controls, but doesn't specifically address building security in from the start.
- C. Separation of Duties divides critical tasks among different individuals to prevent fraud or error, which is an operational control, not a design principle.
- D. Least Privilege ensures users or systems only have the minimum necessary access, which is a specific security control, not a design philosophy.
Security by Design
A cybersecurity principle that mandates building security into the design and architecture of IT systems and applications from the very beginning of the development lifecycle, rather than adding it later.
- Proactive approach to security.
- Reduces vulnerabilities and costs in the long run.
- Integrates security considerations throughout all project phases.
Memory trick: Design with Security, not just for Security.