CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityEasy
A software development company is adopting a DevSecOps approach. As part of this, they are focusing on integrating security activities earlier in the Software Development Life Cycle (SDLC). Which of the following practices BEST represents this 'shift left' security principle?
- AConducting annual security awareness training for all employees.
- BPerforming penetration testing only before production deployment.
- CIntegrating static code analysis into the continuous integration pipeline.
- DImplementing a Security Information and Event Management (SIEM) system for production monitoring.
Show answer & explanationAnswer & explanation
Correct answer: C. Integrating static code analysis into the continuous integration pipeline.
Integrating static code analysis into the continuous integration pipeline means security checks are performed automatically and early in the development process, aligning perfectly with the 'shift left' principle.
Why the other options are wrong
- A. Security awareness training is important but is an organizational control, not a direct 'shift left' practice within the SDLC.
- B. Penetration testing before production is a late-stage activity, opposing 'shift left'.
- D. SIEM for production monitoring is a post-deployment operational security control, not 'shift left' in the SDLC.
Shift Left (DevSecOps)
The practice of integrating security activities and considerations earlier in the Software Development Life Cycle (SDLC) to identify and address vulnerabilities proactively.
- Moves security from end-of-cycle to beginning.
- Reduces cost and effort of fixing vulnerabilities.
- Involves automated security testing in CI/CD pipelines.
Memory trick: Shift Left: Security 'Starts Early' in the 'SDLC journey'.