Certified Information Security Manager (CISM)Information Security ProgramHard

A CISO is tasked with integrating security into the software development lifecycle (SDLC) for a rapidly growing organization that adopts agile methodologies and continuous integration/continuous delivery (CI/CD). The goal is to 'shift left' security without impeding development velocity. Which of the following approaches is MOST aligned with this objective?

  1. AAutomating security testing (SAST, DAST, SCA) within the CI/CD pipeline and integrating vulnerability feedback into developer workflows.
  2. BRequiring all code to be reviewed and approved by the CISO's office before deployment to production.
  3. CImplementing mandatory, manual security reviews by a dedicated security team at the end of each development sprint.
  4. DProviding developers with extensive, in-person security training sessions at the start of every major project.
Show answer & explanation

Correct answer: A. Automating security testing (SAST, DAST, SCA) within the CI/CD pipeline and integrating vulnerability feedback into developer workflows.

Automating security testing within the CI/CD pipeline enables 'shifting left' by providing rapid feedback to developers early in the development cycle. Integrating this feedback directly into their workflows makes security part of the agile process, minimizing friction and maintaining velocity, unlike manual, late-stage reviews or bottlenecks.

Why the other options are wrong

  • B. Requiring CISO approval for every code deployment would be a significant bottleneck, completely undermining development velocity in an agile/CI/CD environment.
  • C. Manual reviews at the end of a sprint create bottlenecks and are antithetical to agile principles, impeding velocity.
  • D. While training is important, 'extensive' and 'in-person' for 'every major project' is not scalable or efficient for rapid development and doesn't directly integrate security into the workflow.

DevSecOps Integration

Integrating security practices and tools throughout the entire software development lifecycle (SDLC), from design to deployment, to 'shift left' security and make it an inherent part of the DevOps process.

  • Automates security testing in CI/CD.
  • Empowers developers with security responsibility.
  • Aims to find and fix vulnerabilities early.

Memory trick: To 'Shift Left Securely', automate tests in the 'DevOps Flow'.

More Information Security Program questions