Study. uk . com
  1. Home
  2. All questions
  3. Question 91

CISM study material · question 91 of 1000

A project plans to gather functional requirements first and add security requirements once the design is stable. Why does SP 800-39 object?

  1. Security requirements apply only from the implementation phase onward
  2. Security requirements are set by the authorising official once the design is stable, because only then is there something concrete to authorise
  3. Security requirements must be gathered before any functional requirement, so that the design starts from the protection the system has to provide
  4. Security requirements are a subset of functional requirements and are incorporated into the life cycle at the same time as the others
Show the answer

Answer: D. Security requirements are a subset of functional requirements and are incorporated into the life cycle at the same time as the others

SP 800-39 treats security requirements as one class of functional requirement, gathered into the life cycle at the same moment as the rest — not bolted on once the design has settled.

Source: NIST SP 800-39 (NIST) — Sec. 2.5 Tier Three — Information Systems View

Challenge yourself on this topic → Study as cards