nerdexam
(ISC)2

SSCP · Question #218

The information security staff's participation in which of the following system development life cycle phases provides maximum benefit to the organization?

The correct answer is D. in parallel with every phase throughout the project. Security is most effective when it is built into every phase of the SDLC rather than bolted on at the end. Participating only in initiation, design, or development misses vulnerabilities introduced in other phases. By engaging in parallel with every phase-from requirements…

Submitted by paula_co· Apr 18, 2026Systems and Application Security

Question

The information security staff's participation in which of the following system development life cycle phases provides maximum benefit to the organization?

Options

  • Aproject initiation and planning phase
  • Bsystem design specifications phase
  • Cdevelopment and documentation phase
  • Din parallel with every phase throughout the project

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    5% (2)
  • D
    90% (36)

Explanation

Security is most effective when it is built into every phase of the SDLC rather than bolted on at the end. Participating only in initiation, design, or development misses vulnerabilities introduced in other phases. By engaging in parallel with every phase-from requirements gathering through retirement-the security team ensures that security requirements are captured early, design decisions are evaluated for risk, code is reviewed during development, and controls are verified before and after deployment. This aligns with the 'security by design' and 'shift-left' principles.

Topics

#SDLC#Security Integration#Security by Design#Proactive Security

Community Discussion

No community discussion yet for this question.

Full SSCP Practice