Nоrdhоlm Systems' security leаd rаnks the cоmpаny's design-phase security activities by how often teams actually do them. Application security configuration comes out on top for sheer frequency of use — yet when the same engineers rate how much it helps security, it scores among the lowest of any design-phase activity. Meanwhile design requirements and abuse-or-misuse cases are both used often *and* rated as genuinely high-impact. Which of the following statements holds up against that pattern? (Select all that apply.)