A CAD replacement project skipped security requirements analysis and plans to "bolt on" controls the week before go-live. What lifecycle guidance should the security architect insist on?
Select an answer to reveal the explanation.
Short Explanation
Bolting locks on after the house is built is expensive and leaky. Security has to ride every stage—from requirements through ops and retirement—not show up as a go-live surprise.
Full Explanation
The information system lifecycle requires security activities from requirements through design, implementation, operation, and disposal. Late bolt-on controls often miss architectural dependencies and acceptance criteria. Insisting on security at each stage is the correct CISSP engineering response to a CAD replacement that skipped early analysis.