Application security must be integrated throughout every phase of development. Thinking about security only during testing is too late, and focusing only on design or development misses crucial aspects. Security considerations should begin at requirements gathering and continue through deployment and maintenance.