Certified Information Security Manager (CISM)Information Security GovernanceMedium

An organization is undergoing a significant digital transformation, adopting cloud-native architectures and DevOps practices. The existing information security governance framework is perceived as slow and rigid. Which of the following principles should the CISO prioritize to adapt the governance framework to this new operational model?

  1. AIntegrate security controls and processes directly into the development and deployment pipelines.
  2. BMaintain existing security policies and procedures to ensure stability during transformation.
  3. CIncrease the number of formal security review committees for all new initiatives.
  4. DCentralize all security decision-making to maintain strict control and consistency.
Show answer & explanation

Correct answer: A. Integrate security controls and processes directly into the development and deployment pipelines.

In cloud-native and DevOps environments, security must be 'shifted left' and integrated throughout the development lifecycle. This involves automating security controls and processes directly into pipelines, enabling rapid, secure deployment without becoming a bottleneck, aligning with agile principles.

Why the other options are wrong

  • B. Maintaining rigid existing policies would likely impede adaptation to new technologies and methodologies.
  • C. Increasing formal committees would add bureaucracy and hinder the speed of digital transformation.
  • D. Centralizing decisions would likely slow down agile processes and create bottlenecks.

Agile Security Governance

An approach to information security governance that emphasizes flexibility, responsiveness, and integration of security into agile development and operational processes.

  • Supports rapid development and deployment cycles.
  • Promotes 'security by design' and 'shift left' principles.
  • Focuses on automation and continuous security.

Memory trick: Security must flow with the digital tide.

More Information Security Governance questions