Security considerations in the information system development life cycle
T Grance, J Hash, M Stevens · 2004
The step 'Security Control Integration' in the Implementation Phase has been changed to read 'System Integration.'Rationale -the original NIST Special Publication (SP) 800-4 was an acquisition process focused guide.In that context, the information system was seen as a series of security controls in need of integration into an organization.As SP 800-64 evolved after the public comment period, it became focused on the System Development Life Cycle.In this context, the term 'Security Control Integration' was confusing because it conflicted with the 'Security Control Development' step.This change more accurately reflects the effort to integrate the system at the operational site.