ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityEasy
A development team is implementing a new customer relationship management (CRM) system. During the coding phase, a junior developer introduces a vulnerability by using an outdated library with known security flaws. Which of the following security practices would have been most effective in preventing this specific issue?
- ARegular security awareness training for all developers.
- BImplementing a robust change management process for code deployments.
- CAutomated static application security testing (SAST) integrated into the CI/CD pipeline.
- DPerforming penetration testing on the completed application.
Show answer & explanationAnswer & explanation
Correct answer: C. Automated static application security testing (SAST) integrated into the CI/CD pipeline.
Automated SAST tools can scan source code and identify known vulnerabilities, including those introduced by outdated or vulnerable libraries, early in the development lifecycle.
Why the other options are wrong
- A. While important, security awareness training might not catch the specific technical oversight of using an outdated library as effectively as an automated tool.
- B. Change management focuses on controlling and documenting changes, not proactively identifying vulnerabilities within the code itself.
- D. Penetration testing occurs much later in the lifecycle and would identify the vulnerability, but SAST would have prevented its introduction or caught it much earlier.
Static Application Security Testing (SAST)
A white-box testing methodology that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application.
- Identifies vulnerabilities early in SDLC (Shift Left)
- Scans code for known patterns and weaknesses
- Does not require a running application
Memory trick: Static scans catch code flaws fast, before they're cast.