Chapter 6. Developers as Partners in Application Security Strategy
Christian Ghigliotty
With the emergence of public cloud providers, developers now have more responsibilities than just writing software to power the business. In many cases, they now have direct responsibilities over security and infrastructure. The additional responsibilities create new challenges for developers, as they are likely operating in spaces they don’t possess deep domain knowledge. These challenges create an opportunity for security teams to foster relationships and feedback loops with development teams to inform a successful long-term application security strategy.
A guiding principle in customer-focused cultures is meeting your customers where they are. If developers are our primary customers, understanding how they build and ship products is crucial to creating experiences that incentivize collaboration and produce positive security outcomes. The continuous integration and continuous delivery/deployment (CI/CD) pipeline—the automated workflow that encourages repeatability, iteration, and code quality—is one of our primary areas of opportunity. Adding select tools to scan code for insecure code patterns, secrets, and vulnerable dependencies creates a set of signals for your program. A well-informed developer’s experience with those findings leads to nuanced discussions that form the basis for a more ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access