ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityMedium

A development team is using an Agile methodology for a new application. Security requirements are being defined, but there is concern that these requirements might be overlooked or misinterpreted during the rapid development sprints. Which of the following practices BEST integrates security into the Agile software development life cycle (SDLC) without significantly hindering agility?

  1. AImplement mandatory, formal security gate reviews after every two sprints, requiring sign-off from a centralized security team.
  2. BEmbed security champions within each development team to provide ongoing guidance and perform security reviews.
  3. CProvide extensive security training to all developers at the beginning of the project and assume they will apply the knowledge.
  4. DConduct a comprehensive security audit only at the end of the final development sprint.
Show answer & explanation

Correct answer: B. Embed security champions within each development team to provide ongoing guidance and perform security reviews.

Embedding security champions directly within development teams ensures continuous security involvement, education, and early identification of issues, aligning well with the iterative nature of Agile without creating bottlenecks. This 'shift-left' approach integrates security from the start.

Why the other options are wrong

  • A. Mandatory, centralized gate reviews can become bottlenecks, slowing down Agile sprints and creating friction between teams.
  • C. While training is important, it's not sufficient on its own to ensure consistent application of security principles throughout a rapid Agile project.
  • D. Waiting until the end for a security audit defeats the purpose of Agile's iterative feedback and can lead to costly late-stage rework.

Security Champion

A developer or team member who acts as a security advocate and expert within their development team, bridging the gap between security and development.

  • Provides immediate security guidance.
  • Promotes secure coding practices.
  • Facilitates communication with the central security team.

Memory trick: Agile security thrives with champions, not just gatekeepers.

More Software Development Security questions