Certified Information Security Manager (CISM)Information Security Risk ManagementMedium

A software development company is adopting a DevSecOps model. The information security manager is tasked with integrating security controls throughout the software development lifecycle (SDLC). Which of the following is the MOST effective way to ensure security is 'shifted left' in this new model?

  1. APerform a final security audit by an independent team just before release.
  2. BImplement automated security testing tools (SAST/DAST) in the continuous integration/continuous deployment (CI/CD) pipeline.
  3. CProvide security awareness training to developers once a year.
  4. DConduct penetration testing only after the application is deployed to production.
Show answer & explanation

Correct answer: B. Implement automated security testing tools (SAST/DAST) in the continuous integration/continuous deployment (CI/CD) pipeline.

Shifting left means integrating security earlier in the SDLC. Automated security testing tools (SAST for static code analysis, DAST for dynamic application analysis) within the CI/CD pipeline ensure that security checks are performed continuously and early in the development process, identifying vulnerabilities before they become costly to fix in later stages.

Why the other options are wrong

  • A. A final audit is a late-stage control, not an early integration of security.
  • C. Annual training is beneficial but doesn't integrate security directly into the development process or 'shift left' as effectively as automated tools.
  • D. Penetration testing in production is 'shifted right' and finds issues late in the cycle, making them expensive to fix.

Shift Left Security

The practice of integrating security activities and considerations earlier in the software development lifecycle (SDLC).

  • Aims to find and fix vulnerabilities early, reducing cost.
  • Involves developer education, automated testing, and secure design.
  • Key principle of DevSecOps.

Memory trick: Shift Left: secure early, save later.

More Information Security Risk Management questions