Certified Information Security Manager (CISM)Information Security ProgramHard
A CISO is developing an information security program for a rapidly growing startup. The startup's culture emphasizes agility and rapid innovation, with frequent changes to products and processes. To ensure the security program remains effective and doesn't hinder growth, which characteristic should the CISO prioritize in the program's design?
- AImplementation of a perimeter-focused security strategy with robust firewalls and intrusion prevention systems.
- BIntegration of security controls and processes into the existing agile development and DevOps pipelines.
- CRigid adherence to a single, comprehensive security framework like ISO 27001 from day one.
- DFocus on manual, detailed security reviews and approvals for every code change.
Show answer & explanationAnswer & explanation
Correct answer: B. Integration of security controls and processes into the existing agile development and DevOps pipelines.
For an agile, innovative startup, integrating security directly into existing development and operational workflows (DevSecOps) is crucial. This makes security a natural part of the process, rather than an impediment, aligning with the culture of agility and supporting rapid, secure innovation.
Why the other options are wrong
- A. A perimeter-focused strategy is insufficient for modern cloud-native or microservices architectures typical of startups; security needs to be integrated throughout the application lifecycle.
- C. Rigidly adopting a comprehensive framework from day one might be too slow and bureaucratic for a fast-paced startup, potentially hindering agility.
- D. Manual, detailed reviews for every code change would significantly slow down development, directly contradicting the startup's emphasis on rapid innovation.
DevSecOps Integration
The practice of integrating security activities and considerations into every phase of the software development lifecycle and IT operations, fostering collaboration between development, security, and operations teams.
- Embeds security into agile and DevOps workflows.
- Enables continuous security and rapid feedback.
- Supports 'shift-left' security principles.
Memory trick: For a fast-moving startup, security must be built-in, not bolted-on.