nerdexam
Isaca

CISM · Question #574

An organization is looking to incorporate DevSecOps practices to enhance the security of applications used for processing large volumes of data. Which of the following is the BEST course of action…

The correct answer is B. Integrate security controls into continuous integration/continuous deployment (CI/CD) pipelines. Integrating security controls into CI/CD pipelines aligns with DevSecOps principles and ensures security is embedded throughout the development lifecycle, which supports the organization’s information security strategy proactively and continuously.

Submitted by kevin_r· Apr 18, 2026Information Security Program Development and Management

Question

An organization is looking to incorporate DevSecOps practices to enhance the security of applications used for processing large volumes of data. Which of the following is the BEST course of action to ensure alignment with the organization’s information security strategy?

Options

  • AEnsure all data is encrypted at rest and in transit before processing.
  • BIntegrate security controls into continuous integration/continuous deployment (CI/CD) pipelines.
  • CLimit application development to in-house teams to reduce the risk of external security threats.
  • DFocus primarily on post-deployment penetration testing for applications.

How the community answered

(40 responses)
  • A
    10% (4)
  • B
    80% (32)
  • C
    3% (1)
  • D
    8% (3)

Explanation

Integrating security controls into CI/CD pipelines aligns with DevSecOps principles and ensures security is embedded throughout the development lifecycle, which supports the organization’s information security strategy proactively and continuously.

Topics

#DevSecOps#Application Security#CI/CD Security#Secure SDLC

Community Discussion

No community discussion yet for this question.

Full CISM Practice