Chapter 38. Data Security Starts with Good Governance
Lauren Maffeo
In some ways, walking through Vancouver Convention Centre in May 2023 felt like déjà vu: I had attended the same summit (The Linux Foundation Open Source Summit North America in the same location (beautiful British Columbia) five years earlier. Many of the same sights, projects, and faces graced my presence. Still, I saw a distinct difference from 2018, when there was little to no talk of open source’s role in application security.
By 2023, security had its own track at the OS Summit, and a brand new project, the Open Source Security Foundation (OpenSSF), had a full day of programming along with a new home under the Linux Foundation’s umbrella. The surge in recent breaches caused by insecure coding practices, lack of encryption, and inadequate access controls means that AppSec can no longer be ignored. Likewise, AppSec teams can’t ignore the role of data governance in their efforts. I suspect that five years from now, data governance won’t be swept under the AppSec rug like it is today.
Data governance—your strategy for the people, processes, and tools to manage big data at scale —can sound like a buzzkill. It’s often conflated with legalese, or it is made the scapegoat for why teams can’t innovate. The truth is much more optimistic: done well, data governance engages colleagues across silos to cocreate the standards ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access