CRISC Certified in Risk and Information Systems ControlGovernanceMedium
A technology start-up is rapidly scaling its operations and wants to implement an agile development methodology. The board of directors, while supportive of innovation, emphasizes the need for robust security and compliance controls. To ensure that security and compliance risks are adequately addressed within this agile environment, which of the following is the MOST crucial organizational structure element?
- AIntegrating security and compliance specialists directly into agile development teams.
- BMandating regular external security audits for all new product increments.
- CEstablishing a centralized 'security and compliance' review board for all releases.
- DCreating a dedicated 'security champion' role within each agile development team.
Show answer & explanationAnswer & explanation
Correct answer: A. Integrating security and compliance specialists directly into agile development teams.
Integrating security and compliance specialists directly into agile development teams ensures that security is 'shifted left' and built into the development process from the beginning, rather than being an afterthought. This proactive approach is essential for agile environments where rapid iterations occur.
Why the other options are wrong
- B. External audits are reactive and provide a snapshot in time; they are not as effective as continuous, integrated security efforts for proactively managing risks in an agile, rapidly evolving environment.
- C. A centralized review board can become a bottleneck in an agile environment, slowing down releases and potentially leading to security being addressed too late in the development cycle.
- D. While helpful, a 'security champion' often lacks the authority and deep expertise of a specialist, and may not fully integrate security activities into the team's daily workflow.
DevSecOps Integration
The practice of embedding security considerations and specialists throughout the entire software development lifecycle (SDLC) in an agile or DevOps environment.
- Shifts security 'left' to earlier stages of development.
- Fosters collaboration between development, security, and operations teams.
- Automates security testing and compliance checks for continuous assurance.
Memory trick: Agile Pace, Secure Space, Embed to Embrace.