ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityMedium
A legacy application is being re-engineered due to high maintenance costs and security vulnerabilities. The development team is considering various strategies to improve security. Which strategy, focused on fundamental changes to the application's architecture and design, represents the most effective long-term approach to mitigating systemic vulnerabilities?
- AImplementing a Web Application Firewall (WAF) to protect the existing application.
- BPerforming regular vulnerability scans and patching identified weaknesses.
- CAdopting a secure-by-design architecture, such as microservices with strong isolation.
- DConducting extensive penetration testing after each major re-engineering phase.
Show answer & explanationAnswer & explanation
Correct answer: C. Adopting a secure-by-design architecture, such as microservices with strong isolation.
Adopting a secure-by-design architecture, like microservices with strong isolation, fundamentally re-engineers the application to incorporate security from its core, addressing systemic vulnerabilities rather than patching symptoms. This is a long-term, proactive approach.
Why the other options are wrong
- A. A WAF provides a layer of protection but does not address fundamental architectural flaws within the application itself.
- B. Vulnerability scanning and patching are reactive measures that address specific findings, not systemic architectural weaknesses.
- D. Penetration testing identifies vulnerabilities but does not, by itself, represent a fundamental architectural change to mitigate systemic issues.
Secure by Design
An approach to software development that ensures security considerations are integrated into every phase of the development lifecycle, from initial design to deployment and maintenance.
- Security built-in, not bolted-on
- Proactive rather than reactive
- Focuses on architecture, principles, and practices
Memory trick: Build security in, from the ground up, then vulnerabilities won't fill your cup.