Certified Information Security Manager (CISM)Information Security Risk ManagementMedium
A software development company is experiencing an increase in security-related defects being discovered late in the development cycle, leading to costly rework and project delays. The CISO wants to implement a security testing methodology that integrates security checks earlier in the Software Development Life Cycle (SDLC). Which of the following would be the MOST effective approach to identify code vulnerabilities during the coding phase, before runtime?
- APenetration testing.
- BDynamic Application Security Testing (DAST).
- CRuntime Application Self-Protection (RASP).
- DStatic Application Security Testing (SAST).
Show answer & explanationAnswer & explanation
Correct answer: D. Static Application Security Testing (SAST).
Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code for security vulnerabilities without actually executing the application. This allows for the identification of defects early in the coding phase, aligning with the 'shift-left' security principle.
Why the other options are wrong
- A. Penetration testing is typically performed on a deployed application, much later than the coding phase.
- B. DAST tests the application in its running state, which is later in the SDLC.
- C. RASP protects applications during runtime, not during the coding phase for defect identification.
Static Application Security Testing (SAST)
A white-box testing method that analyzes application source code, bytecode, or binary code to detect security vulnerabilities without executing the application.
- Performed early in the SDLC (coding phase).
- Identifies vulnerabilities in non-running code.
- Helps 'shift left' security.
Memory trick: SAST: Scan the Code, Catch it Early.