Project Initiation and Planning

Including security requirements in project initiative and planning ensures that timelines, budgets, and deliverables account for security at every phase.

4 slides · 1 min read · Domain 8

Slide 1

Projects usually start out with an idea, a vision, or some conceptual objective. These may address business needs, or a better way of doing things.

At this point, justification for the project's undertaking must be expressed and endorsed by the appropriate levels of organizational management and leadership. This type of information is typically contained in a document that outlines the project's objectives, scope, strategies, and other important factors, such as an estimate of cost or schedule.

Management approval for the project is based on this project plan document, and all undertakings should be cost justified. Security must be involved during this phase, as understanding the security requirements begins here. Security activities need to be done in parallel with project initiation activities and with every single phase guided by the methodology used.

The figure breaks down this first phase of the Software Development Life Cycle (SDLC) and highlights some key security activities that should be included.

Establish User Requirements Identify Alternatives

Determine Security Requirements Conduct Risk Analysis

Establish Classification Gulde

Select/Approve Approach

Define Security Strategy

A variety of checklists can help identify important considerations that would be helpful to your organization in addressing security requirements in the project initiation phase.

The activities listed in the figure above represent a sample drawn from such checklists; there may be other important considerations that any given organization may need to evaluate

Test this domain