A county is building a new benefits-enrollment application. Leadership proposes a single security review one week before go-live. What SDLC practice should security advocate instead?
Select an answer to reveal the explanation.
Short Explanation
Bolting a security stamp on the night before launch is theater. Bake checkpoints into requirements, design, build, test, and upkeep—like inspections at every floor of a building, not only the ribbon-cutting.
Full Explanation
Secure SDLC practice integrates security activities and gates throughout the life cycle rather than concentrating review solely at release. Requirements, design, implementation, testing, and maintenance each need proportionate security tasks for applications that handle citizen benefits data. End-loaded review leaves expensive defects and missed controls. Continuous integration of security reduces rework and aligns with CISSP Domain 8 expectations for development security.