A new municipal records system is entering architectural design. What must occur regarding security before that design hardens?
Select an answer to reveal the explanation.
Short Explanation
You cannot draw a safe blueprint until people say what "safe" means for them. Gather stakeholder needs, write security requirements, then design. Design-first guesswork misses retention, privacy, and access rules.
Full Explanation
In the information system lifecycle, stakeholder needs inform security requirements, which in turn constrain architectural design. Capturing those needs early prevents costly redesign and missed controls for records systems with legal and privacy obligations. Reversing the order embeds gaps into the architecture.