Certified Information Security Manager (CISM)Information Security GovernanceMedium
An organization is considering adopting a new cloud-based customer relationship management (CRM) system. The CISO is asked to assess the information security implications. Which of the following activities should the CISO prioritize to ensure appropriate information security governance is applied to this new system?
- AConduct a penetration test of the new CRM system once it is fully deployed.
- BDevelop a detailed incident response plan specifically for the new CRM system.
- CEnsure that information security requirements are integrated into the system's acquisition and development lifecycle.
- DReview the cloud provider's physical security controls and data center specifications.
Show answer & explanationAnswer & explanation
Correct answer: C. Ensure that information security requirements are integrated into the system's acquisition and development lifecycle.
Integrating security requirements early into the system's acquisition and development lifecycle (SDLC/SLC) is a proactive governance measure. It ensures security is 'built-in' rather than 'bolted-on,' making it more effective and cost-efficient.
Why the other options are wrong
- A. Penetration testing is a valuable validation activity, but it occurs later in the lifecycle. Integrating security from the beginning is a more fundamental governance priority.
- B. An incident response plan is crucial, but it's a reactive measure. Proactive integration of security requirements throughout the lifecycle is a more fundamental governance activity.
- D. While important, reviewing physical controls is one aspect of due diligence. The priority is establishing a governance framework for the entire system lifecycle.
Security in System Lifecycle (SLC)
The practice of embedding security considerations and activities into every phase of a system's acquisition, development, and operational lifecycle, from planning to disposal.
- Ensures security is 'built-in', not 'bolted-on'.
- More cost-effective to address security early.
- Crucial for effective information security governance over new systems.
Memory trick: Build security in, from the start, for the system's heart.