CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceMedium

An organization is deploying a new cloud-native application that handles sensitive customer data. To ensure continuous compliance and security, they decide to integrate security checks and automated policy enforcement directly into their CI/CD pipeline. This includes automated code analysis, container image scanning, and infrastructure-as-code (IaC) security reviews. Which methodology are they primarily adopting?

  1. ADevSecOps
  2. BITIL (Information Technology Infrastructure Library)
  3. CWaterfall Model
  4. DAgile Development
Show answer & explanation

Correct answer: A. DevSecOps

Integrating security checks and automated policy enforcement directly into the CI/CD pipeline, as described, is a core tenet of DevSecOps. This approach 'shifts left' security, making it an integral part of the development and operations process.

Why the other options are wrong

  • B. ITIL is a framework for IT service management, not directly concerned with integrating security into development pipelines.
  • C. The Waterfall Model is a linear, sequential development approach, which is contrary to the continuous integration described.
  • D. Agile Development is a software development methodology focusing on iterative development, but doesn't inherently include security automation in the pipeline.

DevSecOps

An extension of DevOps that integrates security practices into every phase of the software development lifecycle, from initial design to deployment and operations.

  • Shifts security 'left' in the SDLC.
  • Emphasizes automation of security tasks.
  • Promotes collaboration between development, security, and operations teams.

Memory trick: DevSecOps: Security, from start to finish, automatically.

More Governance, Risk and Compliance questions