Mental Models When Developing SoftwareWho Owns Application Security (and Resilience)?Lessons We Can Learn from Database Administration Going DevOpsDecisions on Critical Functionality Before BuildingDefining System Goals and Guidelines on “What to Throw Out the Airlock”Code Reviews and Mental Models“Boring” Technology Is Resilient TechnologyStandardization of Raw MaterialsDeveloping and Delivering to Expand Safety BoundariesAnticipating Scale and SLOsAutomating Security Checks via CI/CDStandardization of Patterns and ToolsDependency Analysis and Prioritizing VulnerabilitiesObserve System Interactions Across Space-Time (or Make More Linear)Configuration as CodeFault Injection During DevelopmentIntegration Tests, Load Tests, and Test TheaterBeware Premature and Improper AbstractionsFostering Feedback Loops and Learning During Build and DeliverTest AutomationDocumenting Why and WhenDistributed Tracing and LoggingRefining How Humans Interact with Build and Delivery PracticesFlexibility and Willingness to ChangeIteration to Mimic EvolutionModularity: Humanity’s Ancient Tool for ResilienceFeature Flags and Dark LaunchesPreserving Possibilities for Refactoring: TypingThe Strangler Fig PatternChapter Takeaways