nerdexam
Isaca

CCAK · Question #119

From the perspective of a senior cloud security audit practitioner in an organization of a mature security program with cloud adoption, which of the following statements BEST describes the DevSecOps…

The correct answer is B. Development standards for addressing integration, testing, and deployment issues. DevSecOps, from a senior cloud security audit practitioner's perspective, is best understood as development standards that embed security requirements across integration, testing, and deployment stages of the SDLC. The governance lens of an auditor frames DevSecOps as a…

Cloud Security Auditing

Question

From the perspective of a senior cloud security audit practitioner in an organization of a mature security program with cloud adoption, which of the following statements BEST describes the DevSecOps concept?

Options

  • AProcess of security integration using automation in software development
  • BDevelopment standards for addressing integration, testing, and deployment issues
  • COperational framework that promotes software consistency through automation
  • DMaking software development simpler, faster, and easier using automation

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    88% (29)
  • C
    3% (1)
  • D
    6% (2)

Why each option

DevSecOps, from a senior cloud security audit practitioner's perspective, is best understood as development standards that embed security requirements across integration, testing, and deployment stages of the SDLC. The governance lens of an auditor frames DevSecOps as a standards discipline rather than a purely technical automation concept.

AProcess of security integration using automation in software development

Describing DevSecOps as only a process of security integration via automation omits the broader standards and governance framework covering testing and deployment that defines the practice from an audit perspective.

BDevelopment standards for addressing integration, testing, and deployment issuesCorrect

From an audit governance perspective, DevSecOps establishes formalized development standards that address security obligations across the full CI/CD pipeline - covering integration, testing, and deployment phases. This framing is what an auditor evaluates: whether repeatable, enforceable standards for security are embedded at each stage of the software delivery lifecycle. Framing DevSecOps as standards rather than just automation reflects the audit practitioner's focus on consistent, auditable control application.

COperational framework that promotes software consistency through automation

This describes a general DevOps automation framework focused on software consistency and does not capture the security integration and standards enforcement that distinguishes DevSecOps from standard DevOps.

DMaking software development simpler, faster, and easier using automation

Simplifying and accelerating development with automation characterizes Agile or general DevOps, not DevSecOps, which specifically focuses on embedding security requirements rather than improving general development velocity.

Concept tested: DevSecOps definition from security audit governance perspective

Source: https://csrc.nist.gov/publications/detail/sp/800-204c/final

Topics

#DevSecOps#SDLC Security#Cloud Security Audit#Automation

Community Discussion

No community discussion yet for this question.

Full CCAK Practice