ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationMedium

An IS auditor is reviewing the system development lifecycle (SDLC) for a critical customer-facing web application. The development team uses an Agile methodology. Which of the following practices BEST ensures that security requirements are adequately addressed throughout the development process?

  1. ARelying on penetration testing by an external vendor once per year.
  2. BProviding security awareness training to all developers at the beginning of the project.
  3. CConducting a comprehensive security audit just before the final production release.
  4. DIntegrating security activities, such as threat modeling and secure code reviews, into each sprint.
Show answer & explanation

Correct answer: D. Integrating security activities, such as threat modeling and secure code reviews, into each sprint.

Integrating security activities into each sprint (often called 'shifting left') ensures that security is built into the application incrementally, addressing vulnerabilities early and reducing remediation costs.

Why the other options are wrong

  • A. Annual penetration testing is a good practice but is reactive and insufficient for continuous security assurance in an Agile, rapidly changing environment.
  • B. While important, security awareness training alone does not guarantee the implementation of secure coding practices or the identification of specific vulnerabilities throughout development.
  • C. A security audit at the end is too late in an Agile process; it would be costly and time-consuming to fix issues found so late.

Security in Agile SDLC

Embedding security practices and considerations throughout all phases of an Agile development lifecycle, rather than as a separate, late-stage activity.

  • Known as 'shifting left' security.
  • Includes continuous threat modeling, secure coding, and testing.
  • Reduces cost and effort of fixing vulnerabilities later.

Memory trick: Shift left for security, sprint by sprint, for agility.

More Domain 3: Information Systems Acquisition, Development and Implementation questions