Information Security
Information Security
Cost
§ It may require additional resources, such as security experts,
to manage the process.
Time-consuming
§ The SSDLC is a cyclical process that involves multiple
phases, which can be time-consuming to implement.
Complexity
SECURITY IN THE SYSTEMS DEVELOPMENT LIFE CYCLE § The SSDLC process can be complex, especially for
PHASES organizations that have not previously used this framework.
System Analysis
§ detailed document analysis of the documents from the
System Investigation phase are done.
§ Upcoming threat possibilities are also analyzed.
§ Risk management comes under this process only
Logical Design
§ deals with the development of tools and following blueprints
that are involved in various information security policies, their
applications and software.
§ Backup and recovery policies are also drafted in order to
prevent future losses
Physical Design
§ diSerent solutions are investigated for any unforeseen issues
which may be encountered in the future.
§ They are analyzed and written down in order to cover most of
the vulnerabilities that were missed during the analysis phase
Implementation
§ The solution decided in earlier phases is made final whether
the project is in-house or outsourced.
§ The proper documentation is provided of the product in order
to meet the requirements specified for the project to be met
Maintenance
§ After the implementation of the security program it must be
ensured that it is functioning properly and is managed
accordingly.
§ The security program must be kept up to date accordingly in
order to counter new threats that can be left unseen at the
time of design
Improved security
§ Organizations can ensure that their information security
systems are developed, maintained and retired in a
controlled and structured manner, which can help to improve
overall security.
Compliance
§ The SSDLC can help organizations to meet compliance
requirements, by ensuring that security controls are
implemented to meet relevant regulations.
Risk management
§ The SSDLC provides a structured and controlled approach to
managing information security risks, which can help to
identify and mitigate potential risks.