CRISC Certified in Risk and Information Systems ControlGovernanceHard
A financial technology (FinTech) startup is developing a new mobile payment application. The application will handle sensitive customer financial data and must comply with various payment card industry (PCI DSS) standards and emerging data privacy regulations (e.g., GDPR, CCPA). The development team is agile and focused on rapid feature deployment. To ensure security and compliance are embedded from the outset, what is the MOST effective approach for the CRISC professional to recommend?
- ASchedule a comprehensive security audit and penetration test immediately before the application launch.
- BHire a dedicated compliance officer to review all code changes for regulatory adherence.
- CImplement a DevSecOps methodology, integrating security and compliance checks into every stage of the development pipeline.
- DProvide extensive training to the development team on secure coding practices and data privacy regulations.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement a DevSecOps methodology, integrating security and compliance checks into every stage of the development pipeline.
Implementing a DevSecOps methodology is the most effective approach because it integrates security and compliance as continuous, automated processes throughout the entire agile development lifecycle, ensuring that these concerns are addressed proactively and iteratively, rather than as a late-stage add-on.
Why the other options are wrong
- A. A pre-launch audit is a single point-in-time check; it is reactive and often too late to efficiently address fundamental security or compliance issues in an agile environment.
- B. While a compliance officer is valuable, reviewing all code changes manually would be a bottleneck in an agile environment and doesn't embed security into the automated pipeline.
- D. Training is important for awareness but does not guarantee the systematic and continuous integration of security and compliance into the development workflow that DevSecOps provides.
DevSecOps Integration
A practice that integrates security and compliance automation into every phase of the software development lifecycle (SDLC), fostering a 'shift-left' approach to identify and mitigate vulnerabilities early and continuously.
- Security is continuous, not an afterthought.
- Automates security checks in CI/CD pipeline.
- Aligns with agile development principles.
Memory trick: Shift security left, integrate it right, keep it tight.