The DevOps Handbook, 2nd Edition
by Gene Kim, Jez Humble, Patrick Debois, John Willis, Nicole Forsgren
23
PROTECTING THE DEPLOYMENT PIPELINE
Throughout this chapter, we will look at how to protect our deployment pipeline, as well as how to achieve security and compliance objectives in our control environment, including change management and separation of duty.
Integrate Security and Compliance into Change Approval Processes
Almost any IT organization of any significant size will have existing change management processes, which are the primary controls to reduce operations and security risks. Compliance managers and security managers place reliance on change management processes for compliance requirements, and they typically require evidence that all changes have been appropriately authorized.
If we have constructed our deployment pipeline correctly ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access