What is a requirement for product security development lifecycles?
A.
Risk management
B.
Agile development
C.
Continuous integration
D.
Defense-in-depth strategy
The Answer Is:
A
This question includes an explanation.
Explanation:
The ISA/IEC 62443-4-1 standard defines the requirements for a secure product development lifecycle for IACS products. One of the core requirements is “risk management” — the systematic process of identifying, evaluating, and mitigating security risks throughout the product lifecycle. This ensures that security is built in from the early design phases through to maintenance and decommissioning. While agile and continuous integration can be useful development methods, they are not specific requirements of the standard. Defense-in-depth is a security principle, not a lifecycle process requirement.