Certified Information Security Manager (CISM)Information Security GovernanceEasy

A financial services organization is considering adopting a new cloud-based customer relationship management (CRM) system. The CISO is responsible for ensuring that the security and compliance requirements are met throughout the system's lifecycle. Which stage of the System Development Life Cycle (SDLC) is MOST critical for integrating security requirements to avoid costly rework later?

  1. ATesting and Quality Assurance
  2. BRequirements Gathering and Design
  3. CImplementation and Deployment
  4. DMaintenance and Operations
Show answer & explanation

Correct answer: B. Requirements Gathering and Design

Integrating security requirements during the Requirements Gathering and Design phase is most critical. Addressing security early prevents costly fixes and architectural changes later in the SDLC.

Why the other options are wrong

  • A. Testing identifies vulnerabilities, but fixing them at this stage is more expensive than preventing them during design.
  • C. Security controls are implemented here, but the requirements for them should have been defined earlier.
  • D. Maintenance includes ongoing security, but foundational security must be established much earlier.

Security in SDLC: Early Integration

Embedding security considerations and controls into the earliest phases of the System Development Life Cycle (SDLC) to prevent vulnerabilities and reduce remediation costs.

  • Cost-effective to fix issues early.
  • Security by design, not by afterthought.
  • Requirements and design are foundational phases.

Memory trick: Build security into the blueprint, not just the walls.

More Information Security Governance questions