Full AWS Practitioner Certification Question

Your company is planning on implementing a security process within their DevOps pipelines. They want to ensure the right testing strategy is conducted during the various phases in the DevOps pipeline. Which of the following should ideally be done during the planning phase?