Microsoft セキュリティ開発ライフサイクル (SDL) に基づいてアプリケーション ライフサイクル管理プロセスを作成しています。 アプリケーションを Azure にオンボードするためのセキュリティ標準を推奨する必要があります。この標準には、アプリケーションの設計、開発、展開に関する推奨事項が含まれます。アプリケーションの設計段階で何を含めるべきでしょうか?
正解:C
The Threat Modeling Tool is a core element of the Microsoft Security Development Lifecycle (SDL). It allows software architects to identify and mitigate potential security issues early, when they are relatively easy and cost-effective to resolve. As a result, it greatly reduces the total cost of development. Also, we designed the tool with non-security experts in mind, making threat modeling easier for all developers by providing clear guidance on creating and analyzing threat models. https://docs.microsoft.com/en-us/azure/security/develop/threat-modeling-tool