Certified Information Security Manager (CISM)Information Security GovernanceHard

An organization is undergoing a significant digital transformation, adopting cloud-native architectures and DevOps practices to accelerate software delivery. The existing information security governance framework, designed for on-premise, waterfall development, is proving to be a bottleneck. The CISO needs to adapt the governance framework to support this agile environment. Which characteristic is MOST crucial for the updated information security governance framework?

  1. ACentralization of all security decision-making within the CISO's office.
  2. BStrict adherence to a predetermined, annual security budget.
  3. CEmphasis on comprehensive, upfront documentation for all security controls.
  4. DIntegration of security controls and feedback loops into continuous delivery pipelines.
Show answer & explanation

Correct answer: D. Integration of security controls and feedback loops into continuous delivery pipelines.

In agile and DevOps environments, security governance must be continuous and integrated. Embedding security controls and feedback directly into CI/CD pipelines ensures security is 'shift-left' and keeps pace with rapid development, avoiding bottlenecks.

Why the other options are wrong

  • A. Centralizing all security decision-making can create bottlenecks and goes against the decentralized, empowered team approach common in agile/DevOps.
  • B. While budgeting is important, rigid annual budgeting can hinder the flexibility required for agile security responses.
  • C. Comprehensive upfront documentation is characteristic of waterfall and can impede agile delivery, which favors working software over extensive documentation.

Agile Security Governance

Adapting information security governance principles and practices to support agile development and DevOps methodologies, emphasizing continuous integration, automation, and rapid feedback loops.

  • Security integrated throughout the lifecycle.
  • Emphasizes automation and continuous monitoring.
  • Supports rapid iteration and delivery.
  • Shifts security 'left' in the development process.

Memory trick: Security should flow with the code, not block it.

More Information Security Governance questions