CRISC · Question #2
An organization has made a decision to purchase a new IT system. During when phase of the system development life cycle (SDLC) will identified risk MOST likely lead to architecture and design trade- o
The correct answer is C. Initiation. During the Initiation phase of the SDLC, identified risks are most likely to lead to architecture and design trade-offs because fundamental system requirements and feasibility are still being defined.
Question
An organization has made a decision to purchase a new IT system. During when phase of the system development life cycle (SDLC) will identified risk MOST likely lead to architecture and design trade- offs?
Options
- AAcquisition
- BImplementation
- CInitiation
- DOperation and maintenance
How the community answered
(41 responses)- A5% (2)
- B7% (3)
- C85% (35)
- D2% (1)
Why each option
During the Initiation phase of the SDLC, identified risks are most likely to lead to architecture and design trade-offs because fundamental system requirements and feasibility are still being defined.
The Acquisition phase involves purchasing decisions, which typically occur after architecture and design choices have largely been solidified, making trade-offs at this point more costly.
The Implementation phase involves building or configuring the system based on established designs; making fundamental architecture changes at this stage is highly disruptive and expensive.
The Initiation phase is where high-level requirements are defined and feasibility is assessed; identifying risks at this early stage allows for fundamental architectural and design adjustments or trade-offs to be made without incurring significant rework costs associated with later phases.
The Operation and maintenance phase is post-deployment, where major architecture and design modifications due to newly identified risks are extremely costly and can significantly impact ongoing business operations.
Concept tested: SDLC risk integration
Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-fedramp-nist-800-53-security-assessment-framework#system-development-life-cycle-sdlc-security
Topics
Community Discussion
No community discussion yet for this question.