CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityEasy
A software development team is adopting a DevSecOps approach. To ensure security is integrated from the earliest stages of the development lifecycle, which of the following practices should be implemented FIRST?
- AAutomated security scanning in the CI/CD pipeline.
- BThreat modeling during the design phase.
- CSecurity awareness training for all developers.
- DRegular penetration testing of production systems.
Show answer & explanationAnswer & explanation
Correct answer: B. Threat modeling during the design phase.
DevSecOps emphasizes 'shifting left,' integrating security early. Threat modeling occurs during the design phase, before any code is written, making it the earliest practical security activity. Automated scanning (A) happens during development/testing. Penetration testing (B) is late-stage. Security awareness training (D) is ongoing but doesn't specifically integrate security into the 'earliest stages' of a project's technical design.
Why the other options are wrong
- A. Automated scanning occurs after code is written, not in the earliest design phase.
- C. Security awareness training is important but is a general ongoing activity, not a specific technical practice integrated into the earliest development stage for a project.
- D. Penetration testing is typically performed on a complete or near-complete system, which is a late-stage activity.
Shift Left (DevSecOps)
The practice of integrating security activities and considerations earlier in the software development lifecycle (SDLC) to identify and address vulnerabilities proactively.
- Aims to find and fix security issues when they are cheaper and easier to resolve.
- Fosters a culture of shared security responsibility.
- Includes practices like threat modeling, secure coding, and static analysis.
Memory trick: Shift Left: 'Start Security Sooner, Save Stress Later'.