CISA · Question #253
When developing customer-facing IT applications, in which stage of the system development life cycle (SDLC) is it MOST beneficial to consider data privacy principles?
The correct answer is C. Requirements definition. Considering data privacy principles during the requirements definition stage of the SDLC is most beneficial because it allows privacy-by-design to be embedded from the very beginning.
Question
When developing customer-facing IT applications, in which stage of the system development life cycle (SDLC) is it MOST beneficial to consider data privacy principles?
Options
- AUser acceptance testing (UAT)
- BSystems design and architecture
- CRequirements definition
- DSoftware selection and acquisition
How the community answered
(38 responses)- A3% (1)
- B11% (4)
- C82% (31)
- D5% (2)
Why each option
Considering data privacy principles during the requirements definition stage of the SDLC is most beneficial because it allows privacy-by-design to be embedded from the very beginning.
User acceptance testing (UAT) is too late to fundamentally integrate privacy principles, as it primarily validates functionality and user experience based on already designed and built features.
While systems design and architecture is important for implementing privacy controls, establishing privacy as a requirement earlier in the requirements definition stage guides the design process itself.
It is MOST beneficial to consider data privacy principles during the requirements definition stage because this allows for "privacy by design," embedding privacy controls and considerations into the fundamental requirements of the application from its inception. Establishing privacy requirements early ensures that data handling practices, consent mechanisms, and data minimization strategies are foundational, preventing costly redesigns later.
Software selection and acquisition might involve evaluating privacy features of third-party tools, but for internally developed customer-facing applications, the focus should be on defining privacy requirements for the new system.
Concept tested: Privacy by Design in SDLC
Source: https://www.nist.gov/privacy-framework/privacy-risk-management/privacy-engineering
Topics
Community Discussion
No community discussion yet for this question.