CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingHard

A software development company uses a continuous integration/continuous delivery (CI/CD) pipeline. During a recent audit, it was found that security testing is only performed at the final stage before deployment, missing vulnerabilities introduced earlier in the development lifecycle. To strengthen control monitoring and effectiveness, the risk manager recommends integrating automated security testing (e.g., SAST, DAST) at earlier stages of the pipeline. This recommendation primarily aims to improve which aspect of control effectiveness?

  1. ACost-effectiveness
  2. BTimeliness of detection
  3. CEase of implementation
  4. DCompliance with regulations
Show answer & explanation

Correct answer: B. Timeliness of detection

Integrating security testing earlier in the CI/CD pipeline (shifting left) allows vulnerabilities to be detected and remediated much sooner in the development process, thereby significantly improving the timeliness of detection. This reduces the cost and effort of fixing issues later on.

Why the other options are wrong

  • A. While earlier detection can lead to cost savings, the primary direct improvement of 'shifting left' security is earlier detection, which then *leads* to cost-effectiveness.
  • C. Integrating new tools might not necessarily increase ease of implementation; it often adds complexity initially, but aims for better outcomes.
  • D. Improved compliance might be a secondary benefit, but the direct aim is to find flaws sooner, not just to meet a regulation.

Shift-Left Security

The practice of integrating security testing and practices earlier into the software development lifecycle to identify and remediate vulnerabilities sooner.

  • Improves timeliness of detection
  • Reduces cost of remediation
  • Enhances overall software security

Memory trick: TIME to be ACCURATE and COVERED!

More Risk Response and Reporting questions