Period that begins when a system is conceived and ends when the system is destroyed. Note 1: Often used synonymously with "system development life cycle (SDLC)", and sometimes defined with formalized steps (e.g. planning, analysis, design, implementation, and maintenance). Note 2: Those responsible for the security of a system will likely not have responsibility for the system throughout its entire life cycle, but should recognize the kinds of risks that may emanate from those areas of the lifecycle outside of their purview (e.g. supply chain risks or post- retirement risks). [ISO/IEC 24765:2017, adapted]
Sources:
CNSSI 4009-2022
Period that begins when a system is conceived and ends when the system is no longer available for use.
Sources:
NIST SP 800-160v1r1
from
ISO/IEC/IEEE 24765:2017