ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityEasy

A development team is implementing a new customer relationship management (CRM) system. During the coding phase, a junior developer introduces a vulnerability by using an outdated library with known security flaws. Which of the following security practices would have been most effective in preventing this specific issue?

  1. ARegular security awareness training for all developers.
  2. BImplementing a robust change management process for code deployments.
  3. CAutomated static application security testing (SAST) integrated into the CI/CD pipeline.
  4. DPerforming penetration testing on the completed application.
Show answer & explanation

Correct answer: C. Automated static application security testing (SAST) integrated into the CI/CD pipeline.

Automated SAST tools can scan source code and identify known vulnerabilities, including those introduced by outdated or vulnerable libraries, early in the development lifecycle.

Why the other options are wrong

  • A. While important, security awareness training might not catch the specific technical oversight of using an outdated library as effectively as an automated tool.
  • B. Change management focuses on controlling and documenting changes, not proactively identifying vulnerabilities within the code itself.
  • D. Penetration testing occurs much later in the lifecycle and would identify the vulnerability, but SAST would have prevented its introduction or caught it much earlier.

Static Application Security Testing (SAST)

A white-box testing methodology that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application.

  • Identifies vulnerabilities early in SDLC (Shift Left)
  • Scans code for known patterns and weaknesses
  • Does not require a running application

Memory trick: Static scans catch code flaws fast, before they're cast.

More Software Development Security questions