Risk management integration with the process life cycle
The security manager should understand that risk management activities are not one-time events. Risk management is a continuous process. For effective risk management, activities related to risk management should be integrated with the process life cycle.
System development life cycle
The security manager should be aware of the following system development life cycle (SDLC) phases:
The security manager should be involved in all the preceding phases of the SDLC and the security requirements should be integrated into all SDLC phases. Performing risk assessments at each stage of the SDLC is the most cost-effective way to address any flaws early.
The following aspects need to be addressed during the risk assessment of the project:
- What level of confidentiality is required for the system?
- What level of availability is required for the system? ...