ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is evaluating an organization's approach to securing its software development lifecycle (SDLC). The organization currently focuses security testing primarily during the 'Testing' phase, just before deployment. The CISA recommends shifting security activities earlier in the SDLC. What is the MOST significant benefit of this 'shift-left' security approach?

  1. AReduced overall development time by integrating security checks directly into coding.
  2. BLower cost of remediation for identified vulnerabilities.
  3. CImproved compliance with regulatory requirements for security testing.
  4. DEnhanced collaboration between development and security teams.
Show answer & explanation

Correct answer: B. Lower cost of remediation for identified vulnerabilities.

The 'shift-left' security approach emphasizes integrating security activities, such as threat modeling, secure coding practices, and static/dynamic application security testing (SAST/DAST), earlier in the SDLC. The most significant benefit is the drastically lower cost of fixing vulnerabilities when they are identified in the design or coding phase, compared to finding and remediating them late in the testing phase or, worse, in production.

Why the other options are wrong

  • A. While efficiency can improve, the primary benefit is cost reduction and improved security, not necessarily reduced overall development time, which can sometimes even increase initially due to new processes.
  • C. Improved compliance is a positive outcome, but it's a consequence of better security practices, not the most direct or significant benefit of shifting left.
  • D. Enhanced collaboration is a positive organizational outcome of shift-left, but the most direct and measurable benefit related to security and cost is the reduced cost of remediation.

Shift-Left Security

The practice of integrating security activities, such as threat modeling, secure coding, and security testing, earlier into the software development lifecycle (SDLC).

  • Aims to find and fix vulnerabilities when they are cheapest and easiest to address.
  • Reduces the overall cost and effort of security remediation.
  • Promotes a culture of 'security by design' and 'DevSecOps'.

Memory trick: Shift 'LEFT' in SDLC to 'SAVE' your wallet.

More Domain 5: Protection of Information Assets questions