CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium
A software development company uses a continuous integration/continuous delivery (CI/CD) pipeline for deploying its applications. To enhance security, the company integrates automated security testing tools (e.g., static application security testing - SAST, dynamic application security testing - DAST) into the early stages of the development cycle, immediately after code is committed and before deployment to production. This approach aligns with which security concept?
- AShift-left security
- BSecurity by obscurity
- CDefense in depth
- DZero Trust Architecture
Show answer & explanationAnswer & explanation
Correct answer: A. Shift-left security
Shift-left security emphasizes moving security activities and testing to earlier stages of the software development lifecycle (SDLC). Integrating SAST and DAST early in the CI/CD pipeline, 'immediately after code is committed,' is a direct application of this principle to find and fix vulnerabilities sooner.
Why the other options are wrong
- B. Security by obscurity relies on hiding vulnerabilities rather than fixing them, which is a poor security practice.
- C. Defense in depth involves multiple layers of security controls, which is a broader concept than shifting security left.
- D. Zero Trust Architecture is a security model that requires strict identity verification for every person and device trying to access resources, regardless of location.
Shift-Left Security
Shift-left security is a practice that integrates security processes, tools, and testing into the earliest phases of the software development lifecycle (SDLC) to identify and address vulnerabilities proactively.
- Moves security from end-of-cycle to beginning.
- Aims to find and fix bugs cheaper and faster.
- Often involves automated testing in CI/CD pipelines.
Memory trick: Shift Left: Secure it early, save it later.