CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

A software development company uses a continuous integration/continuous delivery (CI/CD) pipeline for deploying its applications. To enhance security, the company integrates automated security testing tools (e.g., static application security testing - SAST, dynamic application security testing - DAST) into the early stages of the development cycle, immediately after code is committed and before deployment to production. This approach aligns with which security concept?

  1. AShift-left security
  2. BSecurity by obscurity
  3. CDefense in depth
  4. DZero Trust Architecture
Show answer & explanation

Correct answer: A. Shift-left security

Shift-left security emphasizes moving security activities and testing to earlier stages of the software development lifecycle (SDLC). Integrating SAST and DAST early in the CI/CD pipeline, 'immediately after code is committed,' is a direct application of this principle to find and fix vulnerabilities sooner.

Why the other options are wrong

  • B. Security by obscurity relies on hiding vulnerabilities rather than fixing them, which is a poor security practice.
  • C. Defense in depth involves multiple layers of security controls, which is a broader concept than shifting security left.
  • D. Zero Trust Architecture is a security model that requires strict identity verification for every person and device trying to access resources, regardless of location.

Shift-Left Security

Shift-left security is a practice that integrates security processes, tools, and testing into the earliest phases of the software development lifecycle (SDLC) to identify and address vulnerabilities proactively.

  • Moves security from end-of-cycle to beginning.
  • Aims to find and fix bugs cheaper and faster.
  • Often involves automated testing in CI/CD pipelines.

Memory trick: Shift Left: Secure it early, save it later.

More Risk Response and Reporting questions