CISA Question of the Day: SAST Integration in SDLC

CISA exam practice question — CISA Question of the Day: SAST Integration in SDLC

CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Acquisition, Development and Implementation.

Question

A CISA auditor is evaluating an organization's software development process. Developers occasionally introduce insecure code that is only discovered during release testing, causing delays. Which control would most effectively detect code vulnerabilities early and ensure consistent remediation tracking?

  • A. Require developers to run a local static application security testing (SAST) tool before committing code
  • B. Schedule external SAST assessments by a vendor on a quarterly basis
  • C. Integrate SAST into the continuous integration (CI) pipeline and block builds for critical or high findings
  • D. Have the security team perform manual static code reviews prior to each production release
Show the answer and explanation

Correct answer: C. Integrate SAST into the continuous integration (CI) pipeline and block builds for critical or high findings

Integrating SAST into the CI pipeline with build gating for critical/high findings is best because it automates early detection, enforces consistent policy, and creates traceable results within the development workflow so remediation can be tracked. Requiring developers to run local SAST helps but relies on individual compliance and lacks centralized enforcement and audit trails. Quarterly external assessments are periodic and too infrequent to prevent insecure code from entering releases. Manual reviews by the security team before release create a bottleneck, are resource-intensive, and still detect issues late in the lifecycle.

Want more practice?

Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.