Security features are typically considerednon-functional requirements (NFRs), which should be captured in theproduct backlogand prioritized accordingly. As per thePMI Agile Practice Guide (Section 5.1: Product Backlog)andMike Griffiths' PMI-ACP Exam Prep Book (Chapter 6: Value-Driven Delivery), any requested functionality-whether business- or system-level-must beclearly defined as a backlog itemso the team can plan for it. * Option Ais correct: security requirements should beadded to the backlog and prioritizedlike other features. * Option Bmay come later if implementation is unclear, but first, the work must be defined and logged. * Option CandDrepresent clarification steps but don't directlysupport implementationas backlog management does.