Certified Information Security Manager (CISM)Information Security ProgramMedium
A CISO is integrating security into the organization's agile software development process. Developers are concerned that security gates will slow down release cycles. To address this, the CISO proposes incorporating automated security testing tools and security champions within development teams. Which aspect of the information security program is the CISO primarily enhancing?
- AInformation Security Program Management
- BInformation Security Program Development
- CInformation Security Awareness and Training
- DInformation Security Architecture
Show answer & explanationAnswer & explanation
Correct answer: A. Information Security Program Management
Integrating security into agile development processes via automated testing and security champions falls under Information Security Program Management. This involves the ongoing operation, integration, and improvement of the security program within the organization's processes, rather than just initial development or architecture.
Why the other options are wrong
- B. Program development refers to establishing the program; this scenario describes ongoing integration and optimization within an existing program.
- C. Security champions involve training, but the overall initiative of integrating security into the SDLC is a broader program management activity.
- D. While these activities produce secure architecture, the act of integrating security into the development process is a program management function.
DevSecOps Integration
The practice of integrating security activities and considerations throughout the entire software development lifecycle (SDLC), often leveraging automation and collaboration between development, security, and operations teams.
- Shifts security left (earlier in SDLC).
- Emphasizes automation and security champions.
- Aims to reduce friction and improve security posture in agile environments.
Memory trick: Manage the Flow, Secure the Code, Empower the Team.