The ____ phase of the SecSDLC begins with a directive from upper management, dictating the process, outcomes, and goals of the project, as well as its budget and other constraints.
Frequently, this phase begins with an enterprise information security policy (EISP), which outlines the implementation of a security program within the organization.