ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is reviewing an organization's approach to securing its software development lifecycle (SDLC). The organization currently focuses security testing primarily on the User Acceptance Testing (UAT) phase, just before deployment. What is the MOST significant drawback of this approach?

  1. ADifficulty in automating security testing tools.
  2. BReduced responsiveness to market demands for new features.
  3. CLack of developer training on secure coding practices.
  4. DIncreased cost and effort to fix vulnerabilities found late in the SDLC.
Show answer & explanation

Correct answer: D. Increased cost and effort to fix vulnerabilities found late in the SDLC.

Finding and fixing vulnerabilities late in the SDLC, such as during UAT, is significantly more expensive and time-consuming than addressing them earlier in the development process. This is because changes at this stage often require extensive rework, retesting, and potential delays to deployment.

Why the other options are wrong

  • A. The difficulty in automation is a separate issue; the problem here is the timing of the testing, regardless of automation capabilities.
  • B. While delays might occur, the primary drawback is the cost and effort of late-stage fixes, not necessarily the inability to meet market demands.
  • C. This is a root cause of vulnerabilities, but the question asks about the drawback of finding them late, not why they exist.

Shift-Left Security

An approach to software security that emphasizes integrating security activities and testing earlier in the software development lifecycle (SDLC) to identify and remediate vulnerabilities more efficiently and cost-effectively.

  • Identifies vulnerabilities when they are easier and cheaper to fix.
  • Promotes a security-first mindset among developers.
  • Reduces the risk of costly post-deployment security incidents.

Memory trick: Fixing a leaky pipe after the basement floods is way more expensive than fixing it during construction.

More Domain 5: Protection of Information Assets questions