Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security
Software Development Life Cycle (SDLC): Phases and Models
Updated 11 October 2026 · Fact-checked
The **Software Development Life Cycle (SDLC)** is a structured process for planning, building, testing, deploying and maintaining software. Its phases are planning, requirements analysis, design, development, testing, deployment and maintenance. Models such as waterfall, agile, spiral and DevOps arrange these phases differently. In exams, name the phase or model, explain it, then apply it to the facts.
Understand Software Development Life Cycle (SDLC)
Software is not built in one step. Teams need to decide what to build, how to build it, and how to keep it working. The SDLC is the framework that organises this work into phases, so that cost, time, quality and risk stay under control.
The usual phases are:
- Planning: define scope, feasibility, budget, team and timeline.
- Requirements analysis: gather what users and the business need, and record it in a requirements document.
- Design: decide architecture, database, interfaces and security controls.
- Development (coding): write the code as per the design.
- Testing: check that the software meets requirements and find defects and vulnerabilities.
- Deployment: release the software to the live environment.
- Maintenance: fix bugs, apply patches, and add enhancements after release.
A model decides how these phases are sequenced. In the waterfall model, each phase is completed before the next begins, in a straight line. It suits projects with fixed, well-understood requirements, but changes are costly once a phase is closed. The agile model builds software in short cycles (iterations or sprints). Each cycle delivers a working piece, and the customer gives feedback often. It suits projects where requirements change.
The spiral model repeats the phases in loops, with risk analysis in every loop. It suits large, high-risk projects. DevOps joins development and operations teams. It uses automation, continuous integration and continuous delivery (CI/CD) so that software is released quickly and reliably.
Security must be part of every phase. A secure SDLC adds security activities from the start: security requirements, threat modelling during design, secure coding, security testing, and patching after release. Fixing a flaw late costs far more than preventing it early. This links the topic to software vulnerabilities and the legal duty to keep reasonable security practices.
Key rules to remember
- Phases of SDLC (in order)
- Planning → Requirements → Design → Development → Testing → Deployment → Maintenance
- Some books merge or rename phases. Keep the order and say which version you follow.
- Waterfall model
- Linear: finish one phase, then start the next
- Best for stable requirements. Weak when change is likely.
- Agile model
- Short iterations (sprints) + frequent feedback = working software in small increments
- Best for changing requirements and close customer involvement.
- Spiral model
- Each loop = plan + risk analysis + build + evaluate
- Risk analysis in every loop is the key feature.
- DevOps
- Development + Operations + automation (CI/CD)
- Aims at fast, frequent and reliable releases.
- Secure SDLC
- Security activity in every phase, not only at testing
- Shift security left: address it early in the cycle.
How to solve Software Development Life Cycle (SDLC) questions
Use this method for any question on SDLC phases, models or secure development.
- 1Read the question and mark whether it asks for phases, a model, a comparison or a case application.
- 2Define SDLC in one line: a structured process to plan, build, test, deploy and maintain software.
- 3List the phases in order, with one line on the purpose of each. Use only the phases the question needs.
- 4If a model is asked, state how it arranges the phases, its strength and its limitation.
- 5For a comparison, use clear points such as approach, flexibility, customer involvement, risk handling, cost of change and suitability.
- 6For a case, pick the model that fits the facts (fixed or changing requirements, risk level, release speed) and justify the choice.
- 7Add the security link: name the security activity in each relevant phase.
- 8Close with a one-line conclusion that answers the question asked.
Quickest way: Match the facts to the model
When to use it: Use when a case question asks which SDLC model suits a company or project.
- Look for the key signal in the facts.
- Fixed, clear requirements and formal sign-offs point to waterfall.
- Changing requirements and frequent customer feedback point to agile.
- Large, costly or high-risk project points to spiral.
- Need for rapid, automated, frequent releases points to DevOps.
- Write the model, the reason from the facts, and one drawback.
Common mistakes in Software Development Life Cycle (SDLC)
Listing the SDLC phases in the wrong order, such as testing before development.
Students memorise names without the logic of the flow.
Fix: Remember the story: plan, find needs, design, build, test, release, maintain.
Saying agile has no planning or documentation.
Agile is described as flexible, so students assume it is unstructured.
Fix: Say agile plans in short cycles and values working software and feedback. It is disciplined, not unplanned.
Treating waterfall as always bad and agile as always good.
Textbook comparisons are one-sided.
Fix: Say each suits a different situation. Waterfall fits stable requirements; agile fits changing ones.
Confusing the spiral model with agile because both are iterative.
Both repeat cycles.
Fix: Link spiral to risk analysis in every loop, and agile to short sprints with customer feedback.
Placing security only in the testing phase.
Students think of security as a final check.
Fix: Show security in every phase: requirements, threat modelling in design, secure coding, security testing, patching.
Treating DevOps as a separate phase list instead of a culture and practice.
It appears alongside models in notes.
Fix: Describe DevOps as collaboration of development and operations with automation, CI/CD and monitoring.
Worked examples
Example 1
Distinguish between the waterfall model and the agile model of SDLC.
Show the solution
- Define both: waterfall is a linear, phase-by-phase model; agile is an iterative model with short cycles.
- Approach: waterfall completes each phase before the next starts; agile repeats planning, building and testing in each sprint.
- Change: waterfall handles change poorly once a phase is closed; agile welcomes change between sprints.
- Customer involvement: in waterfall it is mostly at the start and end; in agile it is continuous.
- Delivery: waterfall delivers the full product at the end; agile delivers working increments early.
- Suitability: waterfall suits fixed, well-defined requirements; agile suits evolving requirements.
Answer: Waterfall is linear, sequential and suited to stable requirements, with delivery at the end. Agile is iterative, flexible and customer-focused, with working increments delivered in each sprint.
Example 2
Arjun Textiles Ltd. is building a customer-facing order app. Requirements are likely to change as customers give feedback, and the board wants new features released every few weeks. The board is also worried about data security. Advise on the suitable SDLC approach.
Show the solution
- Provision: SDLC is a structured process, and the model must suit the project's needs.
- Facts: requirements will change, feedback is frequent, and releases are needed every few weeks.
- Analysis: waterfall would make change costly, so it does not fit. Agile fits because it works in sprints and uses feedback. Adding DevOps practices such as CI/CD supports regular, automated releases.
- Security: adopt a secure SDLC. Record security requirements at the start, do threat modelling in design, follow secure coding, run security testing in every sprint, and patch after release.
- Compliance point: keep documented records of security testing and patching, as these help show reasonable security practices.
Answer: Arjun Textiles should use the agile model, supported by DevOps practices, within a secure SDLC that builds security into every sprint and records it for compliance.
Exam tips
- Learn the seven phases in order and write one purpose line for each.
- For comparison questions, give at least five points in a clear list and end with suitability.
- In case questions, quote the facts that decide the model before naming it.
- Always add a security point. A secure SDLC line earns marks in this paper.
- Mention both strength and limitation of each model to show balanced analysis.
Practice questions from Softwares and Software Security
- Which feature distinguishes a copyleft open-source licence such as the GNU General Public License from a permissive licence such as MIT?
- A company's web form builds a database query by directly joining user-typed text into the SQL string. Which control is the most effective pr…
- Sharma Textiles uses a licensed accounting package. An employee installs a cracked copy of the same package on a personal computer. Under In…
- A manufacturing firm's staff find that a vendor's software has a serious flaw that is not yet known to the vendor, and attackers are already…
- A disgruntled software engineer at an Indian firm embeds code in the payroll system that will delete salary records if his own employee ID i…
Software Development Life Cycle (SDLC): frequently asked questions
What are the phases of SDLC?
The common phases are planning, requirements analysis, design, development, testing, deployment and maintenance. Some books use slightly different names or merge phases. Write the order clearly and explain each phase's purpose.
What is the difference between waterfall and agile?
Waterfall is linear, with each phase finished before the next begins. Agile works in short iterations with continuous feedback. Waterfall suits fixed requirements and agile suits changing ones.
What is a secure SDLC?
It is an SDLC in which security activities are part of every phase. These include security requirements, threat modelling, secure coding, security testing and timely patching. The aim is to prevent flaws early rather than fix them late.
When should the spiral model be used?
Use it for large, complex or high-risk projects. Each loop includes risk analysis, so risks are found and reduced before the project goes further.