ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is reviewing an organization's security controls for its software development lifecycle (SDLC). The CISA notes that security testing, including static and dynamic analysis, is performed only at the end of the development cycle, just before deployment. What is the PRIMARY risk associated with this approach?

  1. ADevelopers will lack immediate feedback on secure coding practices.
  2. BThe software may not comply with regulatory security standards.
  3. CThe cost of fixing identified vulnerabilities will be significantly higher.
  4. DSecurity testing results may be inconsistent with business requirements.
Show answer & explanation

Correct answer: C. The cost of fixing identified vulnerabilities will be significantly higher.

Identifying vulnerabilities late in the SDLC (just before deployment) means that significant rework may be required to fix design flaws or fundamental coding errors. This significantly increases the cost and effort of remediation compared to finding and fixing issues earlier in the development process.

Why the other options are wrong

  • A. While true, this is a contributing factor to 'B' (higher cost of fixing), not the primary risk of late testing itself.
  • B. Non-compliance is a consequence, but the *primary risk* of late testing is the financial and time burden of fixing issues found at that stage.
  • D. Inconsistency with business requirements is more related to requirements gathering, not the timing of security testing.

Shift-Left Security

The practice of integrating security activities and testing earlier in the software development lifecycle (SDLC) to identify and remediate vulnerabilities proactively.

  • Reduces the cost and effort of fixing vulnerabilities.
  • Improves overall software quality and security.
  • Encourages developers to adopt secure coding practices.

Memory trick: Finding bugs at the finish line means a costly re-run of the whole race.

More Domain 5: Protection of Information Assets questions