Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium
A software development team is adopting a 'shift-left' security approach and wants to integrate security checks as early as possible into their development workflow. They are particularly interested in ensuring that all code changes are scanned for vulnerabilities and misconfigurations before they are even considered for merging into the main branch. Which stage in the typical CI/CD pipeline is the ideal point to introduce these initial security checks?
- ARuntime application protection
- BPull request initiation and code review
- CPost-deployment monitoring and alerting
- DDeployment to production environment
Show answer & explanationAnswer & explanation
Correct answer: B. Pull request initiation and code review
Integrating security checks at the pull request initiation and code review stage is ideal for 'shift-left' because it allows vulnerabilities and misconfigurations to be identified and addressed before the code is merged into the main branch, preventing issues from progressing further down the pipeline.
Why the other options are wrong
- A. Runtime protection addresses issues in live applications, which is after deployment and not 'shift-left' in the development process.
- C. Post-deployment monitoring is reactive, occurring after potential issues have been deployed.
- D. Deployment to production is too late for a 'shift-left' approach, as issues are already in deployable code.
Shift-Left in CI/CD
The practice of integrating security activities and testing earlier in the software development lifecycle (SDLC) and CI/CD pipeline to identify and remediate vulnerabilities and misconfigurations as soon as possible.
- Reduces the cost and effort of fixing issues.
- Empowers developers with early feedback.
- Includes activities like static analysis, IaC scanning, and secret detection at the code commit/PR stage.
Memory trick: Shift left, security's best start.