Certified Information Security Manager (CISM)Information Security GovernanceMedium

An organization is undergoing a significant digital transformation, adopting cloud-native architectures and DevOps practices. The CISO recognizes that traditional security governance models may hinder agility. To ensure security keeps pace with the new operational model, which of the following approaches should the CISO adopt?

  1. AIntegrate security controls and automated checks directly into the CI/CD pipeline.
  2. BIncrease the frequency of external security audits for cloud environments.
  3. CEnforce strict, centralized security policy approval processes for all new deployments.
  4. DDevelop separate security policies specifically for cloud and DevOps teams.
Show answer & explanation

Correct answer: A. Integrate security controls and automated checks directly into the CI/CD pipeline.

To align with cloud-native and DevOps agility, security must become an integral part of the development and deployment process. Integrating security controls and automated checks directly into the CI/CD pipeline (DevSecOps) ensures security is 'baked in' from the start, rather than being a bottleneck or afterthought, thus maintaining agility.

Why the other options are wrong

  • B. Increasing external audits is a reactive measure and does not integrate security into the agile development process.
  • C. Strict, centralized approvals would counteract the agility inherent in cloud-native and DevOps practices.
  • D. Developing separate policies may be necessary, but this option alone doesn't address the integration of security into agile practices; it's a documentation effort.

Agile Security Governance

An approach to information security governance that emphasizes flexibility, speed, and continuous integration of security into agile development and operational processes, often through DevSecOps practices.

  • Supports rapid development cycles.
  • Embeds security into CI/CD.
  • Prioritizes automation and continuous monitoring.

Memory trick: For speed and security, build it in from the start line to the finish line.

More Information Security Governance questions