SSCP Systems Security Certified PractitionerSystems and Application SecurityHard
A security engineer is designing a secure software development lifecycle (SDLC) for a critical application. They want to ensure that security is integrated at every phase, from requirements gathering to deployment and maintenance. Which of the following is the BEST approach to achieve this 'security by design' philosophy?
- AConducting a comprehensive penetration test just before deployment.
- BOutsourcing all security testing to a third-party vendor at the end of development.
- CRelying solely on a Web Application Firewall (WAF) to protect the deployed application.
- DIntegrating security requirements, threat modeling, and static/dynamic analysis throughout the SDLC.
Show answer & explanationAnswer & explanation
Correct answer: D. Integrating security requirements, threat modeling, and static/dynamic analysis throughout the SDLC.
Integrating security requirements, threat modeling, and various testing methods (static/dynamic analysis) throughout all phases of the SDLC ensures that security is considered from the outset and continuously addressed, embodying the 'security by design' principle.
Why the other options are wrong
- A. A penetration test at the end is good but doesn't integrate security throughout the entire lifecycle; it's a reactive measure.
- B. Outsourcing testing at the end is similar to option A; it's a late-stage activity and doesn't integrate security throughout the SDLC.
- C. Relying solely on a WAF is a perimeter defense and doesn't address vulnerabilities inherent in the application's design or code.
Secure SDLC (Security by Design)
An approach to software development that integrates security considerations and practices into every phase of the Software Development Life Cycle (SDLC), from initial design and requirements gathering through to deployment and maintenance.
- Shifts security 'left' in the development process.
- Aims to prevent vulnerabilities rather than just detect them late.
- Involves threat modeling, secure coding, security testing, and secure deployment.
Memory trick: Build security in from the start, not just a patch at the end.