Who should perform the design review to uncover security design flaws as part of the Software Development Life Cycle (SDLC)?
Correct Answer: B
A security subject matter expert (SME) should perform the design review to uncover security design flaws as part of the Software Development Life Cycle (SDLC). A security SME has the knowledge and experience to identify and mitigate potential security risks and vulnerabilities in the design phase, before they become costly and difficult to fix in later stages. The business owner, the application owner, and the developer SME may not have the sufficient security expertise or perspective to conduct a thorough and effective design review.
References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 21: Software Development Security, page 2010.