The board of directors of a software development company is concerned about the organization's ability to innovate rapidly while maintaining a strong security posture. They question if security is integrated effectively into strategic planning. To address this, the CISO proposes a new approach. Which of the following best describes this approach?
- AEmbedding security requirements and risk considerations into the early stages of all new business initiatives.
- BImplementing a 'security sign-off' process that reviews all completed projects before deployment.
- CPrioritizing security investments based solely on the highest number of reported vulnerabilities.
- DEstablishing a separate, independent security department with its own strategic goals.
Show answer & explanationAnswer & explanation
Correct answer: A. Embedding security requirements and risk considerations into the early stages of all new business initiatives.
Embedding security requirements and risk considerations into the early stages of all new business initiatives (Security by Design/Shift Left) is the most effective approach. This proactive integration ensures security is a foundational element, enabling innovation securely rather than becoming a bottleneck at later stages, directly addressing the board's concern.
Why the other options are wrong
- B. A 'sign-off' process at the end of a project is reactive and can delay deployment, contradicting the desire for rapid innovation.
- C. Prioritizing based solely on vulnerability count is a tactical approach and doesn't reflect strategic alignment with business goals or proactive risk management for new initiatives.
- D. A separate, independent security department without integration can reinforce the perception of security as an isolated function, hindering collaboration and innovation.
Security in Strategic Planning
The practice of integrating information security considerations, risk management, and compliance requirements into the foundational stages of an organization's overall strategic planning and new business initiatives.
- Ensures security is proactive, not reactive.
- Aligns security with business innovation and growth.
- Reduces costs and risks by 'baking in' security from the start.
Memory trick: Weave security into the very fabric of every new business idea.