QuestionQ289

Information Security Program

Which of the following represents the PRIMARY role of the information security manager in application development?

  • A To ensure control procedures address business risk
  • B To ensure enterprise security controls are implemented
  • C To ensure compliance with industry best practice
  • D To ensure security is integrated into the system development life cycle (SDLC)
Explanation

Information security management ensures that security requirements, design considerations, testing, and controls are incorporated throughout the system development life cycle (SDLC), rather than being added only after development is complete.

Community Discussion

No comments yet. Be the first to start the discussion!