Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 1 Question 115 Discussion

During which of the following development phases is it MOST challenging to implement security controls?
C) Development phase
A) Post-implementation phase
B) Implementation phase
D) Design phase

Isaca CISM Exam - Topic 1 Question 115 Discussion

Actual exam question for Isaca's CISM exam
Question #: 115
Topic #: 1
[All CISM Questions]

During which of the following development phases is it MOST challenging to implement security controls?

Show Suggested Answer Hide Answer
Suggested Answer: C

The development phase is the stage of the system development life cycle (SDLC) where the system requirements, design, architecture, and implementation are performed. The development phase is most challenging to implement security controls because it involves complex and dynamic processes that may not be well understood or documented. Security controls are essential for ensuring the confidentiality, integrity, and availability of the system and its data, as well as for complying with regulatory and contractual obligations. However, security controls may also introduce additional costs, risks, and constraints to the development process, such as:

Increased complexity and overhead of testing, verification, validation, and maintenance

Reduced flexibility and agility of changing requirements or design

Increased dependency on external vendors or third parties for security services or products

Increased vulnerability to errors, defects, or vulnerabilities in the code or configuration

Increased difficulty in measuring and reporting on security performance or effectiveness

Therefore, implementing security controls in the development phase requires careful planning, coordination, communication, and collaboration among all stakeholders involved in the SDLC. It also requires a clear understanding of the security objectives, scope, criteria, standards, policies, procedures, roles, responsibilities, and resources for the system. Moreover, it requires a proactive approach to identifying and mitigating potential threats or risks that may affect the security of the system.

Reference= CISM Manual1, Chapter 3: Information Security Program Development (ISPD), Section 3.1: System Development Life Cycle (SDLC)2

1: https://store.isaca.org/s/store#/store/browse/cat/a2D4w00000Ac6NNEAZ/tiles2: https://store.isaca.org/s/store#/store/browse/cat/a2D4w00000Ac6NNEAZ/tiles


Contribute your Thoughts:

0/2000 characters
I lean towards the implementation phase as well, but I wonder if the post-implementation phase could also present challenges if vulnerabilities are found later.
upvoted 0 times
...
Roosevelt
5 days ago
I feel like the development phase could also be challenging, but I can't recall the specifics. Maybe it’s about integrating security into the coding process?
upvoted 0 times
...
Sarah
10 days ago
I'm not so sure, but I remember a practice question that suggested the design phase could be tough too since security needs to be built in early.
upvoted 0 times
...
Melissia
15 days ago
I think it might be the implementation phase because that's when everything is being put together, and changes can be tricky.
upvoted 0 times
...

Save Cancel