Skip to Content
DevOpsSec
book

DevOpsSec

by Jim Bird
June 2016
Intermediate to advanced
85 pages
1h 50m
English
O'Reilly Media, Inc.
Content preview from DevOpsSec

Chapter 2. Security and Compliance Challenges and Constraints in DevOps

Let’s begin by looking at the major security and compliance challenges and constraints for DevOps.

Speed: The Velocity of Delivery

The velocity of change in IT continues to increase. This became a serious challenge for security and compliance with Agile development teams delivering working software in one- or two-week sprints. But the speed at which some DevOps shops initiate and deliver changes boggles the mind. Organizations like Etsy are pushing changes to production 50 or more times each day. Amazon has thousands of small (“two pizza”) engineering teams working independently and continuously deploying changes across their infrastructure. In 2014, Amazon deployed 50 million changes: that’s more than one change deployed every second of every day.1

So much change so fast...

How can security possibly keep up with this rate of change? How can they understand the risks, and what can they do to manage them when there is no time to do pen testing or audits, and no place to put in control gates, and you can’t even try to add a security sprint or a hardening sprint in before the system is released to production?

Where’s the Design?

DevOps builds on Agile development practices and extends Agile ideas and practices from development into operations.

A challenge for many security teams already working in Agile environments is that developers spend much less time upfront on design. The Agile manifesto emphasizes “working ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Blazor in Action

Blazor in Action

Chris Sainty
DevSecOps in Kubernetes

DevSecOps in Kubernetes

Wei Lien Dang, Ajmal Kohgadai
Okta Administration: Up and Running

Okta Administration: Up and Running

Lovisa Stenbäcken Stjernlöf, HenkJan de Vries

Publisher Resources

ISBN: 9781491971413Errata Page