A security engineer is designing a Customer Relationship Management (CRM) application for a third-party vendor. In which phase of the System Development Life Cycle (SDLC) will it be MOST beneficial to conduct a data sensitivity assessment?
Correct Answer: B
A data sensitivity assessment is a process of identifying and classifying the data that is involved in a system or application, based on the level of confidentiality, integrity, and availability that is required for the data. A data sensitivity assessment can help to determine the security requirements, controls, and measures that are needed to protect the data from unauthorized access, use, disclosure, modification, or destruction. The phase of the System Development Life Cycle (SDLC) where it will be most beneficial to conduct a data sensitivity assessment is the initiation phase. The initiation phase is the first phase of the SDLC, where the scope, objectives, and feasibility of the system or application are defined and approved. The initiation phase is the best time to conduct a data sensitivity assessment, as it can help to identify the data that is essential for the system or application, and the potential risks and impacts that may affect the data. The data sensitivity assessment can also help to align the security goals and strategies of the system or application with the business goals and strategies of the organization and the stakeholders. The data sensitivity assessment can also help to avoid or reduce the costs and efforts of implementing or changing the security controls and measures in the later phases of the SDLC. Development / Acquisition, Enumeration, or Operation / Maintenance are not the phases of the SDLC where it will be most beneficial to conduct a data sensitivity assessment, as they are either too late or irrelevant for the data sensitivity assessment. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 21: Software Development Security, page 1149; CISSP Official (ISC)2 Practice Tests, Third Edition, Domain 8: Software Development Security, Question 8.2, page 302.