At which stage of risk analysis specification, the additional security requirements take account of the technologies used in building the system and system design and implementation decisions?
(a) Preliminary risk analysis
(b) Life-cycle risk analysis
(c) Operational risk analysis
(d) All of the mentioned
This question was posed to me in an online interview.
This interesting question is from Dependability and Security Specification in division Dependability and Security of Software Engineering