ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationHard

An IS auditor is evaluating the controls over system development for a new e-commerce platform. The auditor discovers that security requirements were only considered during the final testing phase, rather than being integrated throughout the system development lifecycle (SDLC). Which of the following is the MOST significant implication of this approach?

  1. APotential for an increased number of security vulnerabilities in the production system.
  2. BDifficulty in obtaining security certification or compliance after deployment.
  3. CIncreased project costs due to late identification of security flaws.
  4. DDelayed go-live date due to extensive re-work in the final phase.
Show answer & explanation

Correct answer: A. Potential for an increased number of security vulnerabilities in the production system.

Integrating security throughout the SDLC (Shift Left) is crucial. Discovering security flaws only in the final testing phase means that security was not 'built-in' from the start. This significantly increases the likelihood that fundamental architectural or design vulnerabilities will persist and be deployed to production, making the system inherently less secure.

Why the other options are wrong

  • B. Difficulty in certification is a result, but the root problem is the higher number of actual vulnerabilities that will make certification challenging.
  • C. Increased costs are a consequence, but the primary implication is the presence of actual vulnerabilities.
  • D. Delayed go-live is a consequence, but the underlying issue is the compromised security posture of the system.

Security in SDLC (Shift Left)

Integrating security practices and considerations throughout all phases of the System Development Lifecycle (SDLC), rather than as a final step.

  • Identifies and remediates vulnerabilities earlier.
  • Reduces cost and effort of security fixes.
  • Leads to more secure and resilient systems.

Memory trick: Security Last, Vulnerabilities Fast.

More Domain 3: Information Systems Acquisition, Development and Implementation questions