CRISC Certified in Risk and Information Systems ControlGovernanceHard

A large retail company is planning to launch a new mobile payment application that will handle sensitive customer financial data. The development team is operating under an agile methodology with rapid iterations. To ensure that security and compliance are embedded from the outset, which of the following practices is MOST effective in integrating policies, standards, and procedures (PSPs) into this development lifecycle?

  1. AIntegrating security and compliance checks, automated tools, and policy requirements directly into the CI/CD pipeline and sprint planning.
  2. BConducting a comprehensive security audit of the application only after it has been fully developed and deployed.
  3. CProviding developers with a static repository of all corporate PSPs and requiring them to review it annually.
  4. DAppointing a dedicated compliance officer to manually review all code changes for adherence to PSPs before each release.
Show answer & explanation

Correct answer: A. Integrating security and compliance checks, automated tools, and policy requirements directly into the CI/CD pipeline and sprint planning.

Integrating security and compliance checks, automated tools, and policy requirements directly into the CI/CD pipeline and sprint planning is the most effective approach for agile development. This 'shift-left' strategy embeds PSPs into every stage, fostering continuous compliance and security by design, rather than treating them as post-development activities or manual bottlenecks.

Why the other options are wrong

  • B. Post-deployment audits are reactive and costly for agile, missing opportunities to fix issues early.
  • C. A static repository and annual review are insufficient for agile, where rapid changes require continuous integration of PSPs.
  • D. Manual review of all code changes is not scalable or efficient in a rapid agile development environment.

DevSecOps Policy Integration

Embedding security policies, standards, and procedures directly into the development, security, and operations (DevSecOps) pipeline, often through automation and continuous checks.

  • Shifts security 'left' in the lifecycle.
  • Leverages automation for continuous compliance.
  • Essential for agile and rapid development environments.

Memory trick: For agile, security policies must be a 'gear' in the pipeline, not a gate at the end.

More Governance questions