
238 ◾ Information Security Fundamentals
Once the functional specifications are completed and reviewed for security
concerns, it is time to consider the process of development itself. Development
should always be done using coding frameworks that have been tested and are
well respected by industry security experts. Coding should be managed with strict
reference to best practices. Building these elements into the documented require-
ments for the project is a good start in helping guide it in the right direction from
a security perspective, but this alone is not enough. e functional requirements
themselves need to plan for security. Another consideration ...