Certified Cloud Security Professional (CCSP)Cloud Application SecurityEasy

A cloud application development team is adopting a DevSecOps approach. They want to ensure that security is integrated throughout the entire software development lifecycle (SDLC), not just as a final audit. During which phase should security requirements and threat modeling be initially performed?

  1. ADesign/Planning Phase
  2. BImplementation/Coding Phase
  3. CTesting Phase
  4. DDeployment Phase
Show answer & explanation

Correct answer: A. Design/Planning Phase

In a DevSecOps approach, security should be 'shifted left', meaning security activities are integrated as early as possible. Security requirements definition and threat modeling are fundamental design activities that provide a secure foundation for the entire application, making the Design/Planning Phase the ideal starting point.

Why the other options are wrong

  • B. Implementing security during coding is reactive; it's better to define requirements earlier.
  • C. Testing uncovers vulnerabilities, but defining security requirements and threat modeling should precede testing to build security in, not just test for it.
  • D. Deployment is too late to define security requirements; security should be built into the application much earlier.

Shift Left Security

The practice of integrating security activities and considerations early in the software development lifecycle (SDLC), ideally starting in the design and planning phases.

  • Reduces cost of fixing vulnerabilities.
  • Builds security in, rather than bolting it on.
  • Emphasizes proactive security measures.

Memory trick: Shift Left means secure from the start, not just the end.

More Cloud Application Security questions