ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingMedium

A security architect is designing a new cloud-based application and needs to integrate security testing throughout the development lifecycle. They are looking for a strategy that emphasizes testing early and often, automatically, and within the development pipeline. Which approach best describes this strategy?

  1. ATraditional waterfall security gates
  2. BPost-production penetration testing
  3. CAnnual compliance audits
  4. DShift-left security testing
Show answer & explanation

Correct answer: D. Shift-left security testing

Shift-left security testing emphasizes moving security activities, including testing, earlier into the Software Development Life Cycle (SDLC) to identify and remediate vulnerabilities closer to their introduction, making it more efficient and cost-effective.

Why the other options are wrong

  • A. Waterfall security gates typically involve security checks at phase transitions, not continuous integration.
  • B. Post-production testing occurs late, contradicting 'early and often'.
  • C. Annual audits are periodic and retrospective, not integrated 'throughout the development lifecycle'.

Shift-Left Security

An approach to software development that integrates security practices, including testing, earlier into the development lifecycle to find and fix vulnerabilities when they are less costly to address.

  • Security activities moved to earlier SDLC phases
  • Emphasizes automation and continuous integration
  • Reduces cost and effort of vulnerability remediation

Memory trick: Shift Left: Security goes earlier, not later.

More Security Assessment and Testing questions