ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementMedium
A software development company is adopting a DevSecOps approach. As part of this, security teams are integrating automated security tests, code reviews, and vulnerability scanning into the continuous integration/continuous delivery (CI/CD) pipeline. This proactive approach aims to identify and mitigate security flaws early in the software development life cycle. Which risk management strategy is being primarily implemented here?
- ARisk Avoidance
- BRisk Mitigation
- CRisk Transfer
- DRisk Acceptance
Show answer & explanationAnswer & explanation
Correct answer: B. Risk Mitigation
Integrating security tests, code reviews, and vulnerability scanning into the CI/CD pipeline are all actions taken to reduce the likelihood or impact of security flaws. These are classic examples of risk mitigation strategies, as they aim to lower the overall risk.
Why the other options are wrong
- A. Risk Avoidance means eliminating the risk by not performing the activity, which is not the case here as development continues.
- C. Risk Transfer means shifting the financial burden of a risk to another party, like insurance, which is not described.
- D. Risk Acceptance involves taking no action to reduce the risk, which is contrary to the scenario.
Risk Mitigation
The process of reducing the likelihood or impact of a risk event.
- Involves implementing security controls and countermeasures.
- Aims to lower risk to an acceptable level.
- Examples include patching, encryption, access controls, and training.
Memory trick: AART: Avoid, Accept, Reduce, Transfer.