QuestionQ802

Risk Response and Reporting

Which of the following BEST ensures that information-security risk factors are mitigated during the development of in-house applications?

  • A Include information security control specifications in business cases.
  • B Identify key risk indicators (KRIs) as process output.
  • C Identify information security controls in the requirements analysis.
  • D Design key performance indicators (KPIs) for security in system specifications.
Explanation

Identifying information security controls during requirements analysis incorporates security requirements into the system development life cycle early enough for the controls to be designed, implemented, and tested. NIST guidance calls for including information-system security requirements in the SDLC to support the selection and acquisition of appropriate controls.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!