Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium
A company is developing a new cloud-native application that will handle sensitive customer data. The development team wants to ensure that security is integrated throughout the entire software development lifecycle (SDLC), rather than being an afterthought. Which cybersecurity best practice aligns with this approach?
- ASecurity Information and Event Management (SIEM)
- BDisaster Recovery Planning
- CPenetration Testing
- DDevSecOps
Show answer & explanationAnswer & explanation
Correct answer: D. DevSecOps
DevSecOps (Development, Security, and Operations) is an approach that integrates security practices into every phase of the software development lifecycle, from design and development to deployment and operations, making security a shared responsibility.
Why the other options are wrong
- A. SIEM is for collecting and analyzing security logs and events, primarily an operational security tool.
- B. Disaster Recovery Planning focuses on business continuity after an incident, not on integrating security into development.
- C. Penetration Testing is a post-development activity to find vulnerabilities, not an integrated lifecycle approach.
DevSecOps
An organizational software engineering culture and practice that aims to automate, monitor, and apply security at every phase of the software development lifecycle (SDLC), from initial design through integration, testing, deployment, and software delivery.
- Integrates security into all SDLC phases.
- Automates security tasks.
- Promotes collaboration between development, security, and operations teams.
Memory trick: Think 'DevSecOps' as 'Development, Security, Operations' all working together from the start.