ISC2 Certified in Cybersecurity (CC)Security PrinciplesHard

A software development firm is using an agile methodology for a new project. To ensure that security is not an afterthought, they embed security checks and reviews at every stage of the Software Development Life Cycle (SDLC), from requirements gathering to deployment. This proactive integration of security best practices throughout the entire development process is an example of which concept?

  1. ASecurity by Obscurity
  2. BShift-Left Security
  3. CCloud Access Security Broker (CASB)
  4. DJust-in-Time Access
Show answer & explanation

Correct answer: B. Shift-Left Security

Shift-Left Security is a practice that integrates security testing and considerations earlier in the Software Development Life Cycle (SDLC) rather than only at the end. This allows for vulnerabilities to be identified and remediated when they are easier and cheaper to fix.

Why the other options are wrong

  • A. Security by Obscurity relies on secrecy, which is not a robust security principle.
  • C. A Cloud Access Security Broker (CASB) is a security tool for cloud environments, not a development approach.
  • D. Just-in-Time Access is an access management principle, not a development methodology.

Shift-Left Security

A practice that integrates security testing and considerations earlier in the Software Development Life Cycle (SDLC), moving security 'left' on the project timeline.

  • Identifies vulnerabilities early, reducing cost and effort.
  • Promotes a security-first mindset in development.
  • Involves security reviews, static/dynamic analysis, and threat modeling throughout SDLC.

Memory trick: Move security left, find flaws right.

More Security Principles questions