Application security must be considered throughout the entire SDLC - from requirements and design through development, testing, and deployment. Focusing on only one phase (testing, development, or design) leaves vulnerabilities in other phases and is far less effective than continuous security.