ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium

A software development team is adopting a 'shift-left' security approach for a new application. During which phase of the Software Development Life Cycle (SDLC) would security testing be MOST emphasized in this approach?

  1. AProduction and Operations
  2. BTesting and Quality Assurance
  3. CDeployment and Maintenance
  4. DRequirements and Design
Show answer & explanation

Correct answer: D. Requirements and Design

Shift-left security emphasizes integrating security practices and testing as early as possible in the SDLC. The 'Requirements and Design' phase is the earliest point where security considerations can be embedded proactively, making it the most emphasized phase for early security efforts.

Why the other options are wrong

  • A. Production and Operations is too late; finding vulnerabilities here is costly and reactive.
  • B. Testing and Quality Assurance is important, but shift-left pushes security even earlier than this traditional testing phase.
  • C. Deployment and Maintenance is a late stage; shift-left aims to find issues much earlier.

Shift-Left Security

An approach to software development that emphasizes integrating security practices and testing activities earlier in the Software Development Life Cycle (SDLC), rather than at later stages.

  • Aims to find and fix vulnerabilities early
  • Reduces cost and effort of remediation
  • Promotes a security-first mindset among developers

Memory trick: Shift-Left: Move security tasks to the beginning of the SDLC timeline.

More Security Principles questions