Integrating Risk Management in System Development Life Cycle

M. F. Unuakhalu, M. Garikapati · 2014

Abstract: While impossible to eliminate all risk from organizational operations, one of the most effective ways to protect organization assets is through the incorporation of risk management and security into the System Development Life Cycle (SDLC). The paper goes through each phase of the SDLC and provides a minimum set of security steps that needs to be effectively incorporated into a system during its development. Adhering to an SDLC model increases the likelihood of project success, particularly in the area of fulfilling stakeholder requirements. By identifying security requirements early in the development process and incorporating them throughout the SDLC,security objectives will be easily will be met in all systems released from development. The intent is not to disturb or add more phases to the SDLC, but rather to incorporate security activities into an existing SDLC methodology.

Read the paper · More papers on PaperTik