Certified Information Security Manager (CISM)Information Security Risk ManagementEasy
A financial institution is developing a new mobile banking application. The project manager is focused on rapid deployment and feature delivery. The information security manager emphasizes the need to integrate security requirements early in the development lifecycle. Which of the following BEST describes the security manager's recommended approach?
- AProviding security awareness training to end-users after the application is released.
- BAdding a Web Application Firewall (WAF) to protect the application in production.
- CImplementing security architecture reviews and threat modeling during the design phase.
- DConducting a comprehensive penetration test just before the application launch.
Show answer & explanationAnswer & explanation
Correct answer: C. Implementing security architecture reviews and threat modeling during the design phase.
Integrating security requirements early in the development lifecycle, specifically during the design phase through architecture reviews and threat modeling, is a cornerstone of 'security by design.' This proactive approach helps identify and mitigate vulnerabilities before they become costly to fix later.
Why the other options are wrong
- A. End-user training is important but doesn't integrate security into the application's development.
- B. A WAF is a production control, applied after development, not an early integration measure.
- D. Penetration testing is a reactive measure performed late in the cycle.
Security by Design
Security by Design is an approach to software and system development that aims to build security into the initial design and architecture, rather than adding it as an afterthought.
- Integrates security from the outset.
- Reduces vulnerabilities and costs in the long run.
- Involves threat modeling, secure coding, and architecture reviews.
Memory trick: Building security in, not bolting it on later.