CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityHard
A software development team is adopting a 'shift left' security approach for a new application. During which phase of the Software Development Life Cycle (SDLC) would security architecture reviews and threat modeling MOST effectively be conducted to align with this approach?
- AMaintenance Phase
- BTesting Phase
- CDeployment Phase
- DRequirements and Design Phase
Show answer & explanationAnswer & explanation
Correct answer: D. Requirements and Design Phase
The 'shift left' approach advocates integrating security activities as early as possible in the SDLC. Security architecture reviews and threat modeling are design-focused activities that are most effective and cost-efficient when performed during the requirements and design phases, before code is even written.
Why the other options are wrong
- A. Maintenance is reactive; 'shift left' focuses on proactive security integration much earlier.
- B. Testing is too late for 'shift left' for architectural issues, which are expensive to fix then.
- C. Deployment is very late in the cycle; architectural and design flaws would be extremely costly to remediate.
Shift Left (Security in SDLC)
A practice that emphasizes integrating security activities and considerations earlier in the Software Development Life Cycle (SDLC) to identify and address vulnerabilities proactively, reducing costs and risks.
- Moves security from end to beginning of SDLC.
- Early detection is cheaper to fix.
- Includes threat modeling, secure coding, security testing.
Memory trick: Earlier is cheaper, safer, smarter.