Certified Information Security Manager (CISM)Information Security GovernanceHard
The board of directors of a software development company is concerned about the organization's ability to quickly adapt its security posture to emerging threats and changing business priorities. The CISO needs to demonstrate how the information security strategy supports this agility. Which of the following elements of the strategy is MOST crucial to address this concern?
- AA detailed list of all security technologies currently deployed and planned for the next fiscal year.
- BA comprehensive risk register documenting all identified threats and vulnerabilities.
- CAnnual security audits performed by an external, independent third party.
- DIntegration of security into agile development methodologies and continuous delivery pipelines.
Show answer & explanationAnswer & explanation
Correct answer: D. Integration of security into agile development methodologies and continuous delivery pipelines.
Integrating security into agile development and continuous delivery pipelines ensures that security is built-in from the start and continuously adapted as new features are developed and deployed. This embedded approach enables rapid response to changing threats and business priorities, fostering agility.
Why the other options are wrong
- A. A technology list is a snapshot, not an agile strategy for adapting to change.
- B. A risk register identifies risks, but doesn't inherently describe how the strategy enables agile adaptation.
- C. Annual audits are periodic assessments, not mechanisms for continuous, agile adaptation to dynamic changes.
Security in Digital Transformation
Embedding information security practices and considerations directly into modern software development and operational processes, such as Agile and DevOps, to achieve continuous security assurance and responsiveness.
- Enables 'security by design'.
- Supports rapid development cycles.
- Crucial for agile and cloud-native environments.
Memory trick: Agile dev means agile sec.