CAS-002 · Question #799
An internal development team has migrated away from Waterfall development to use Agile development. Overall, this has been viewed as a successful initiative by the stakeholders as it has improved…
The correct answer is D. Agile development has different phases and timings compared to Waterfall. Security activities. Agile is not inherently less secure than Waterfall - security must simply be adapted to fit the iterative sprint-based model rather than being front-loaded as in Waterfall.
Question
An internal development team has migrated away from Waterfall development to use Agile development. Overall, this has been viewed as a successful initiative by the stakeholders as it has improved time-to-market. However, some staff within the security team have contended that Agile development is not secure. Which of the following is the MOST accurate statement?
Options
- AAgile and Waterfall approaches have the same effective level of security posture. They both need
- BAgile development is fundamentally less secure than Waterfall due to the lack of formal up-front
- CAgile development is more secure than Waterfall as it is a more modern methodology which has
- DAgile development has different phases and timings compared to Waterfall. Security activities
How the community answered
(46 responses)- A4% (2)
- B17% (8)
- C9% (4)
- D70% (32)
Why each option
Agile is not inherently less secure than Waterfall - security must simply be adapted to fit the iterative sprint-based model rather than being front-loaded as in Waterfall.
Agile and Waterfall do not have the same security posture by default - they require different security integration strategies, and equating them ignores the fundamental structural differences in how and when security controls are applied.
Agile is not fundamentally less secure than Waterfall - the lack of a formal upfront security phase is compensated by continuous security integration throughout sprints, making this statement technically inaccurate.
Being a more modern methodology does not inherently make Agile more secure - security quality depends on how well security practices are embedded into the process, not on the age or popularity of the methodology.
Agile development integrates security activities differently than Waterfall - rather than a dedicated security phase at the start or end, security reviews, threat modeling, and testing are embedded within each sprint or iteration. This approach, often called DevSecOps or Secure SDLC for Agile, can be equally rigorous when properly implemented. The key distinction is timing and distribution of security activities, not the absence of them.
Concept tested: Integrating security into Agile SDLC
Source: https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.