ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityMedium
A software development team is adopting a DevOps approach, aiming for continuous integration and continuous deployment (CI/CD). To ensure security is integrated throughout this rapid development cycle, which of the following practices is most crucial for 'shifting left' security?
- AEstablishing a bug bounty program after application release.
- BImplementing a dedicated security team for final penetration testing.
- CIntegrating automated security tests (SAST, DAST) into the CI/CD pipeline.
- DConducting annual security audits by an independent third party.
Show answer & explanationAnswer & explanation
Correct answer: C. Integrating automated security tests (SAST, DAST) into the CI/CD pipeline.
Integrating automated security tests like SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) directly into the CI/CD pipeline allows for continuous scanning and early identification of vulnerabilities, embodying the 'shift left' principle in a DevOps environment.
Why the other options are wrong
- A. Bug bounty programs are reactive, identifying vulnerabilities after release, which is the opposite of 'shifting left'.
- B. Penetration testing is a valuable activity, but a dedicated team for final testing occurs late in the cycle, not 'shifting left'.
- D. Annual audits are periodic and retrospective, not continuous or early in the development process.
Shift Left Security
The practice of integrating security activities and considerations earlier in the software development lifecycle (SDLC) to identify and address vulnerabilities proactively, reducing cost and effort.
- Moves security from end-of-cycle to beginning
- Reduces cost of fixing vulnerabilities
- Requires automation and developer involvement
Memory trick: Shift left, test early, errors you'll flee.