Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard
An organization is deploying a new cloud-based application that will handle sensitive customer data. To ensure the application's security and prevent common vulnerabilities, the development team is advised to follow the 'secure by design' principle. Which action is the MOST crucial implementation of this principle?
- AProviding comprehensive security awareness training to end-users after launch.
- BImplementing a robust patch management schedule post-deployment.
- CIntegrating security requirements and threat modeling into every phase of the Software Development Life Cycle (SDLC).
- DConducting penetration tests after the application is fully developed.
Show answer & explanationAnswer & explanation
Correct answer: C. Integrating security requirements and threat modeling into every phase of the Software Development Life Cycle (SDLC).
The 'secure by design' principle emphasizes building security into an application from the very beginning of its development lifecycle, rather than trying to add it as an afterthought. Integrating security requirements and threat modeling into every SDLC phase ensures that security considerations are fundamental to the application's architecture and implementation.
Why the other options are wrong
- A. End-user training is important but addresses human factors, not the inherent security of the application's design.
- B. Patch management is post-deployment maintenance, not integrating security into the design phase.
- D. Penetration testing is reactive and occurs late in the cycle, not 'secure by design'.
Secure by Design
A security principle that advocates for building security into systems and applications from the initial design phase, rather than adding it as an afterthought.
- Proactive approach to security.
- Integrates security throughout the SDLC.
- Reduces vulnerabilities and costs in the long run.
Memory trick: Design security in, don't just bolt it on later.