There are many security tools and techniques that can be used to ensure a secure application, each having its own costs and benefits. As we look at application security through the lens of the business, how can we secure our applications in a cost-effective manner with as little of friction as possible? How can security personnel and developers not just co-exist, but partner to achieve a common goal? Controls implemented throughout the software development life cycle (SDLC) must be strategically assessed and implemented to account for a wide array of business and security objectives.