Certified Information Security Manager (CISM)Information Security Risk ManagementMedium
A software development company is experiencing an increase in security-related defects being discovered late in the development lifecycle, leading to costly rework and project delays. The CISO wants to embed security more effectively into the software development process. Which of the following approaches is MOST effective in addressing this issue?
- AIncrease the number of security auditors reviewing code post-development.
- BImplement static application security testing (SAST) in the build pipeline.
- CConduct penetration testing before every production release.
- DProvide annual security awareness training to developers.
Show answer & explanationAnswer & explanation
Correct answer: B. Implement static application security testing (SAST) in the build pipeline.
Implementing SAST in the build pipeline is a 'shift-left' security practice that automatically identifies vulnerabilities early in the development lifecycle, preventing them from propagating to later, more costly stages.
Why the other options are wrong
- A. Increasing manual reviews post-development is reactive and resource-intensive, still finding issues late.
- C. Penetration testing is a late-stage activity; it finds issues but doesn't prevent them from being introduced early.
- D. Annual training is beneficial but less direct and continuous than automated tooling embedded in the development process for defect reduction.
Static Application Security Testing (SAST)
A 'white-box' testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.
- Identifies vulnerabilities early in the SDLC.
- Works on non-running code.
- Often integrated into CI/CD pipelines.
Memory trick: SAST shifts security left, saving time and stress.