Security is cheapest and most effective when it is built in from the start and carried through to the end of a system's life. The CISSP outline describes an information system lifecycle drawn from systems engineering practice, such as ISO/IEC/IEEE 15288 and the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-160. It runs from understanding stakeholder needs through retirement. The same logic applies whether you build software in-house, buy a commercial product or configure a cloud service.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.