Chapter 32. DevSecOps Is Evolving to Drive a Risk-Based Digital Transformation
Idan Plotnik
Digital transformation has become a board-level discussion. Executives realize that their businesses are being disrupted, and they need to innovate faster than ever in order to gain a competitive advantage and drive consistent growth. DevOps has become synonymous with delivering faster in an Agile manner, but a secure software development life cycle (SDLC) has often been left behind in the constant struggle for speed because it contains manual processes and too many tools that lack the context of risk and business impact. In addition, they are handled by different practitioners in the organization (e.g., developers, security architects, and compliance officers).
DevSecOps is the methodology and practice of inserting security into the DevOps process. Many organizations have found some level of success by automating their existing security processes and calling it “DevSecOps,” but that approach has created other issues, including more alerts and false positives that the security and development teams don’t have the time to research and fully understand in order to effectively remediate risk. With a ratio of one security architect for every 100 developers, DevSecOps has struggled to effectively scale.
Code Security Is Becoming “Security”
What modern DevSecOps practitioners understand is that ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access