An organization is adopting agile development methodology. Which control is MOST critical to ensure security is integrated?
Placing security stories in the product backlog makes security work a first-class, estimated and prioritised deliverable that the team addresses each sprint. This embeds controls into features as they are built, rather than retrofitting them after release, which is the critical mechanism for agile security integration.
Why this answer
In agile development, security must be continuously integrated into each iteration. Including security stories in the product backlog ensures that security tasks are prioritized, estimated, and addressed during each sprint, making security an inherent part of the development lifecycle rather than an afterthought. This aligns with the principle of 'shifting left' on security, where controls are applied as early as possible.
Exam trap
The trap here is that candidates often choose 'Security requirements defined at project initiation' (Option D) because it sounds like early planning, but in agile, requirements must be continuously refined and added to the backlog, not locked in at the start.
How to eliminate wrong answers
Option A is wrong because penetration testing before release is a point-in-time validation that occurs late in the cycle and does not ensure security is integrated throughout development; it can miss vulnerabilities introduced after the test. Option C is wrong because code reviews after each sprint, while valuable for quality, are reactive and may not cover all security aspects (e.g., architecture, threat modeling) that need to be planned as backlog items. Option D is wrong because security requirements defined only at project initiation are static and do not adapt to evolving threats or changes in agile iterations; they must be continuously refined and added as backlog items.