CISM Certified Information Security Manager – Question0401

During which phase of development is it MOST appropriate to begin assessing the risk of a new application system?

A.
Feasibility
B. Design
C. Development
D. Testing

Correct Answer: A

Explanation:

Explanation:
Risk should be addressed as early in the development of a new application system as possible. In some cases, identified risks could be mitigated through design changes. If needed changes are not identified until design has already commenced, such changes become more expensive. For this reason, beginning risk assessment during the design, development or testing phases is not the best solution.