Which two practices help make the security of an application a more integral part of the software development lifecycle? (Choose two.)