An audit finds city policy mandates certificate-based EAP, but nobody reviewed which line-of-business apps break with mutual TLS client auth. What requirements step was skipped?
Select an answer to reveal the explanation.
Short Explanation
Mandating EAP-TLS without checking apps is like requiring passport gates without asking if the buses still fit. Inventory clients and apps first, then lock the EAP method.
Full Explanation
Reviewing client devices and applications is a Domain 1 requirements activity. Mandating EAP-TLS without compatibility analysis can break specialty apps or poorly integrated clients. Requirements gathering should validate application behavior and plan exceptions or remediations before the mandate is enforced.