StudyToCert

All certifications / SecurityX / Lessons

CompTIA SecurityX CAS-005 · Domain 2: Security architecture

Security in the software development life cycle: requirements, secure design reviews, SAST, DAST, SCA and CI/CD pipeline security

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Fixing a security flaw in design costs far less than fixing it in production, so security belongs in every phase of the software development life cycle (SDLC). This approach is often called shifting left, and in DevSecOps security checks are automated in the pipeline so they run on every change.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SecurityX for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SecurityX study plan