Tutor, the longest phase is hopefully the operations and maintenance phase, in which the system is actually used for the business of the business, and consequently the phase where most of the controls of defense in depth are deployed. Defense in Breadth controls mostly apply to the other phases. So the first phase SDLC is initiation - what security controls would apply during the initiation phase of the SDLC?