EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewEasy
An organization is developing a new cloud-based application that will process sensitive customer data. To comply with various industry regulations and data protection laws, the development team is integrating security measures from the initial design phase through deployment. This approach, which aims to reduce vulnerabilities and ensure security by default, is best described as:
- ASecurity by Design
- BDefense in Depth
- CSecurity by Obscurity
- DRisk Acceptance
Show answer & explanationAnswer & explanation
Correct answer: A. Security by Design
Security by Design is an approach where security considerations are integrated into every phase of the software development lifecycle, from initial concept and design to implementation, testing, and deployment. This proactive stance aims to build secure systems from the ground up.
Why the other options are wrong
- B. Defense in Depth involves multiple layers of security controls, but 'Security by Design' specifically refers to integrating security from the start of development.
- C. Security by Obscurity relies on hiding vulnerabilities rather than fixing them, which is a poor security practice.
- D. Risk Acceptance is a risk management strategy where an organization chooses to accept the potential loss from a risk, not a development approach.
Security by Design
An approach to software and system development where security is considered and integrated into every stage of the lifecycle, from initial planning and design through implementation and deployment.
- Proactive security measure.
- Integrates security early in SDLC.
- Aims to prevent vulnerabilities rather than fix them later.
- Leads to more resilient and trustworthy systems.
Memory trick: Design security early, build it strong, don't hide it.