nerdexam
Isaca

CISA · Question #253

When developing customer-facing IT applications, in which stage of the system development life cycle (SDLC) is it MOST beneficial to consider data privacy principles?

The correct answer is C. Requirements definition. Considering data privacy principles during the requirements definition stage of the SDLC is most beneficial because it allows privacy-by-design to be embedded from the very beginning.

Submitted by ricky.ec· Apr 18, 2026Information Systems Acquisition, Development, and Implementation

Question

When developing customer-facing IT applications, in which stage of the system development life cycle (SDLC) is it MOST beneficial to consider data privacy principles?

Options

  • AUser acceptance testing (UAT)
  • BSystems design and architecture
  • CRequirements definition
  • DSoftware selection and acquisition

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    11% (4)
  • C
    82% (31)
  • D
    5% (2)

Why each option

Considering data privacy principles during the requirements definition stage of the SDLC is most beneficial because it allows privacy-by-design to be embedded from the very beginning.

AUser acceptance testing (UAT)

User acceptance testing (UAT) is too late to fundamentally integrate privacy principles, as it primarily validates functionality and user experience based on already designed and built features.

BSystems design and architecture

While systems design and architecture is important for implementing privacy controls, establishing privacy as a requirement earlier in the requirements definition stage guides the design process itself.

CRequirements definitionCorrect

It is MOST beneficial to consider data privacy principles during the requirements definition stage because this allows for "privacy by design," embedding privacy controls and considerations into the fundamental requirements of the application from its inception. Establishing privacy requirements early ensures that data handling practices, consent mechanisms, and data minimization strategies are foundational, preventing costly redesigns later.

DSoftware selection and acquisition

Software selection and acquisition might involve evaluating privacy features of third-party tools, but for internally developed customer-facing applications, the focus should be on defining privacy requirements for the new system.

Concept tested: Privacy by Design in SDLC

Source: https://www.nist.gov/privacy-framework/privacy-risk-management/privacy-engineering

Topics

#SDLC#Data Privacy#Privacy by Design#Requirements Gathering

Community Discussion

No community discussion yet for this question.

Full CISA Practice