In which phase of the System Development Lifecycle (SDLC) is Security Accreditation Obtained?
Correct Answer: B
A project management tool that can be used to plan, execute, and control a
software development project is the systems development life cycle (SDLC). The SDLC is a
process that includes systems analysts, software engineers, programmers, and end users in the
project design and development.
Because there is no industry-wide SDLC, an organization can use any one, or a combination of
SDLC methods.
The SDLC simply provides a framework for the phases of a software development project from
defining the functional requirements to implementation. Regardless of the method used, the SDLC
outlines the essential phases, which can be shown together or as separate elements.
The model chosen should be based on the project. For example, some models work better with
long-term, complex projects, while others are more suited for short-term projects. The key element
is that a formalized SDLC is utilized.
The number of phases can range from three basic phases (concept, design, and implement) on
up.
The basic phases of SDLC are:
Project initiation and planning
Functional requirements definition
System design specifications
Development and implementation
Documentation and common program controls
Testing and evaluation control, (certification and accreditation)
Transition to production (implementation)
The system life cycle (SLC) extends beyond the SDLC to include two additional phases:
Operations and maintenance support (post-installation)
Revisions and system replacement
The following answers are incorrect:
Functional Requirements Phase
Acceptance Phase
Postinstallation Phase
The following reference(s) were/was used to create this question:
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition
((ISC)2 Press) (Kindle Locations 11790-11809). Auerbach Publications. Kindle Edition.