CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityHard

A software development team is adopting a 'shift left' security approach for a new application. During which phase of the Software Development Life Cycle (SDLC) would security architecture reviews and threat modeling MOST effectively be conducted to align with this approach?

  1. AMaintenance Phase
  2. BTesting Phase
  3. CDeployment Phase
  4. DRequirements and Design Phase
Show answer & explanation

Correct answer: D. Requirements and Design Phase

The 'shift left' approach advocates integrating security activities as early as possible in the SDLC. Security architecture reviews and threat modeling are design-focused activities that are most effective and cost-efficient when performed during the requirements and design phases, before code is even written.

Why the other options are wrong

  • A. Maintenance is reactive; 'shift left' focuses on proactive security integration much earlier.
  • B. Testing is too late for 'shift left' for architectural issues, which are expensive to fix then.
  • C. Deployment is very late in the cycle; architectural and design flaws would be extremely costly to remediate.

Shift Left (Security in SDLC)

A practice that emphasizes integrating security activities and considerations earlier in the Software Development Life Cycle (SDLC) to identify and address vulnerabilities proactively, reducing costs and risks.

  • Moves security from end to beginning of SDLC.
  • Early detection is cheaper to fix.
  • Includes threat modeling, secure coding, security testing.

Memory trick: Earlier is cheaper, safer, smarter.

More Information Technology and Security questions