A software development company uses a DevOps methodology and deploys code multiple times a day. To maintain compliance with internal security policies and external regulations, security checks must be integrated into the continuous integration/continuous deployment (CI/CD) pipeline without significantly slowing down development. Which of the following would be the MOST effective approach to achieve this balance?
- ARely solely on developer code reviews for security vulnerabilities.
- BConduct quarterly manual penetration tests on production systems.
- CImplement static application security testing (SAST) in the commit stage and dynamic application security testing (DAST) in the staging environment.
- DPerform annual security audits by an external third party.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement static application security testing (SAST) in the commit stage and dynamic application security testing (DAST) in the staging environment.
Integrating SAST (Static Application Security Testing) early in the commit stage provides rapid feedback on code vulnerabilities without running the application, fitting the CI/CD speed. DAST (Dynamic Application Security Testing) in the staging environment then tests the running application for vulnerabilities, providing a comprehensive check before production. This combination offers continuous, automated security checks throughout the pipeline, aligning with DevOps principles and compliance needs.
Why the other options are wrong
- A. Relying solely on developer code reviews is insufficient; it lacks automation, can miss complex vulnerabilities, and introduces human error, making it inadequate for robust compliance in a fast-paced environment.
- B. Quarterly manual penetration tests are too infrequent and slow for a daily deployment cycle and would not provide continuous security feedback.
- D. Annual security audits are important for overall compliance but are not granular or frequent enough to provide continuous security assurance for daily deployments.
DevSecOps
An approach that integrates security practices into every phase of the software development lifecycle (SDLC), from design to deployment and operations, ensuring security is a shared responsibility across development, operations, and security teams.
- Integrates security throughout SDLC.
- Automates security testing.
- Fosters a 'shift-left' security mindset.
Memory trick: Shift Left, Automate, Integrate, Monitor.