nerdexam
Isaca

CISM · Question #963

Which of the following should be done FIRST to ensure information security is integrated in system development projects?

The correct answer is D. Define security requirements. Defining security requirements (D) must happen first because it establishes the foundational criteria that all subsequent development decisions are measured against - without them, there is nothing concrete to implement, assign, or enforce. Reviewing the security policy (A) is…

Submitted by satoshi_tk· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following should be done FIRST to ensure information security is integrated in system development projects?

Options

  • AReview the security policy.
  • BEmbed a security representative in each project team.
  • CAssign resources based on the business impact.
  • DDefine security requirements.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    16% (4)
  • D
    72% (18)

Explanation

Defining security requirements (D) must happen first because it establishes the foundational criteria that all subsequent development decisions are measured against - without them, there is nothing concrete to implement, assign, or enforce. Reviewing the security policy (A) is a useful input to defining requirements, but a policy is high-level guidance, not project-specific requirements. Embedding a security representative (B) is a governance mechanism that supports implementation, but representation without defined requirements gives that person nothing actionable to work from. Assigning resources based on business impact (C) is a prioritization activity that logically follows requirements, since you cannot size the effort until you know what security outcomes are needed.

Memory tip: Think "Requirements before Resources, Representatives, or Reviews" - you must know what security means for the project before you can staff it, fund it, or validate it against policy.

Topics

#SDLC Security#Security Requirements Definition#Secure Development#Information Security Integration

Community Discussion

No community discussion yet for this question.

Full CISM Practice