Certified Information Security Manager (CISM)Information Security Risk ManagementMedium

A software development company is adopting a DevSecOps model to integrate security into every stage of the software development lifecycle (SDLC). The information security manager is tasked with ensuring that security vulnerabilities are identified and addressed as early as possible. Which of the following practices is MOST effective in achieving this goal within a DevSecOps environment?

  1. AConducting annual penetration tests on production systems.
  2. BPerforming dynamic application security testing (DAST) on staging environments before deployment.
  3. CImplementing automated static application security testing (SAST) in the code commit pipeline.
  4. DMandating security awareness training for all developers once a year.
Show answer & explanation

Correct answer: C. Implementing automated static application security testing (SAST) in the code commit pipeline.

DevSecOps emphasizes 'shifting left' security, meaning integrating security early. Automated SAST in the code commit pipeline allows for immediate detection of vulnerabilities as code is written, providing rapid feedback to developers and preventing insecure code from progressing, which is the earliest possible stage.

Why the other options are wrong

  • A. Annual penetration tests are late-stage and reactive, contrary to the 'shift-left' principle of DevSecOps.
  • B. DAST in staging is good but occurs later than SAST in the commit pipeline, as code has already been built and deployed to an environment.
  • D. Security awareness training is foundational but does not directly identify vulnerabilities in code during development.

Static Application Security Testing (SAST)

A white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.

  • Identifies vulnerabilities early in SDLC.
  • Does not require a running application.
  • Suitable for 'shift-left' security.

Memory trick: Shift Left: Find bugs before they even become code.

More Information Security Risk Management questions