As the world increasingly moves to the cloud and digital-everything, organizations risk postures have also changed. Embedding security into the business is the new, must-have approach and product security is the most seamless path to make it happen led by the emergence of the engineering-centric CISO
Many top performers like Netflix, Github, Square have proven that integrating security into writing, building, and shipping code is one of the single most effective ways to improve overall security posture. Thats why mass adoption of DevSecOps is one of the biggest post-pandemic security trends.
Frankly, DevSecOps was already a hot topic pre-pandemic. As the quality and productivity benefits of DevOps have become well-established, layering in security and shifting left with DevSecOps followed as the next logical step.
However, even in 2022, many organizations are still in the early stages of their DevSecOps journey. Security is still often the team of no. Instead of being integrated into the SDLC from the start, security is tacked on post-deployment with vulnerability scanners and penetration tests.
The good news is that businesses recognize the gap and are trying to implement DevSecOps practices. A Cloud Security Alliance (CSA) report (PDF) found that 89% of organizations are actively adopting DevSecOps. Most of those organizations are still in the planning, designing, or implementing phases of their DevSecOps journey, which is indicative of where the market is headed.
In these early stages, organizations need to navigate the cultural and human side of DevSecOps adoption. Security has to stop being the team of no and become ingrained with the development lifecycle. Getting Shift Left right means leaning into the idea that security is everyones responsibility and making security a seamless part of the pipeline instead of something that happens post-deployment.
Getting Shift Left Right: A DevSec Ops Manifesto
What does that mean for the future of the DevSecOps? Heres a short manifesto with implications for the market:
Culture and mindset are more important than tools. I cant overstate this point. Automation and tools are important, but adopting DevSecOps starts with a culture shift. Making the shift from security as a single teams job which often creates an almost combative relationship between security and development to security as a shared responsibility takes time, effort, and dedication. This creates significant demand for consultancies that can help businesses successfully achieve a smooth transition.
Software provenance and software composition analysis (SCA) must become a priority. Supply chain attacks, protestware, and opensource vulnerabilities like Log4Shell have made the importance of securing libraries and dependencies clear. Applications today depend on a wide range of software from third parties, and a security flaw in just one package can have a huge ripple effect. DevSecOps platforms like JFrog and GitLab make it easy for teams to secure their dependencies and trace software provenance can address this problem while easing the adoption of DevSecOps.
Tooling needs to remove friction from security. For DevSecOps to be effective, security needs to be integrated directly into software delivery pipelines. If security integrations create bottlenecks and impede productivity, teams will begin to bypass them. Security must become part of how developers write, build, and deploy, not a separate process. Thats why its imperative for DevSecOps tools to tightly integrate with DevOps workflows. Examples of tooling getting this right include Synk and Veracode.
DevSecOps tooling needs to handle compliance challenges. Compliance with standards like HIPAA, PCI-DSS, and SOX is a must for many businesses. Keeping up with all the audits, scans, and requirements often involves significant manual effort. Compliance as code solutions like Concourse Labs and IBMs opensource Trestle (based on NISTs OSCAL models) can add a lot of value here. By streamlining the compliance process with DevSecOps tooling and practices, teams can demonstrate business value and help create a positive feedback loop for broader DevSecOps adoption.
(Youll notice Ive left AppSec tooling out of the mix here. While important, and likely more primed for growth, AppSec is a distinct category that we should view as complementary to DevSecOps. The difference is simple: DevSecOps is everything from code to deploy, AppSec is post-deploy.)
To summarize, most organizations want to adopt DevSecOps practices, but their current practices are closer to traditional waterfall methodologies than the agile practices described in the DevSecOps manifesto above.
Therefore, the immediate hurdle facing most businesses is overcoming the challenges related to people and processes. For providers of DevSecOps services and solutions, the focus should be on removing friction from integrating security and helping teams come together to make security everyones responsibility.
Read more from the original source:
The VC View: The DevSecOps Evolution and Getting "Shift Left" Right - SecurityWeek
- EvolutionM.net - Mitsubishi Lancer Evolution | Reviews, News ... [Last Updated On: June 12th, 2016] [Originally Added On: June 12th, 2016]
- Evolution - Wikipedia, the free encyclopedia [Last Updated On: June 19th, 2016] [Originally Added On: June 19th, 2016]
- Darwin's Theory Of Evolution [Last Updated On: June 22nd, 2016] [Originally Added On: June 22nd, 2016]
- Evolution - Conservapedia [Last Updated On: June 28th, 2016] [Originally Added On: June 28th, 2016]
- History of Evolution | Internet Encyclopedia of Philosophy [Last Updated On: June 28th, 2016] [Originally Added On: June 28th, 2016]
- Darwin's Theory Of Evolution [Last Updated On: June 28th, 2016] [Originally Added On: June 28th, 2016]
- Evolution - Simple English Wikipedia, the free encyclopedia [Last Updated On: June 29th, 2016] [Originally Added On: June 29th, 2016]
- Evolution (2001) - IMDb [Last Updated On: July 5th, 2016] [Originally Added On: July 5th, 2016]
- Introduction to Human Evolution | The Smithsonian Institution ... [Last Updated On: July 7th, 2016] [Originally Added On: July 7th, 2016]
- EvolutionM.net - Mitsubishi Lancer Evolution | Reviews, News ... [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- Evolution - Biology-Online Dictionary [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- Introduction to Human Evolution | The Smithsonian Institution ... [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- Evolution - Bulbapedia, the community-driven Pokmon encyclopedia [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- What is Evolution - explanation and definitions [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- Apps/Evolution - GNOME Wiki! [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- History of Evolution | Internet Encyclopedia of Philosophy [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- Recent Articles | Evolution | The Scientist Magazine [Last Updated On: July 16th, 2016] [Originally Added On: July 16th, 2016]
- Evolution - The New York Times [Last Updated On: July 25th, 2016] [Originally Added On: July 25th, 2016]
- Evolution : Pictures , Videos, Breaking News [Last Updated On: August 2nd, 2016] [Originally Added On: August 2nd, 2016]
- Faculty & Staff - Biology | Biology | High Point University ... [Last Updated On: August 8th, 2016] [Originally Added On: August 8th, 2016]
- Evolution (software) - Wikipedia, the free encyclopedia [Last Updated On: September 2nd, 2016] [Originally Added On: September 2nd, 2016]
- Evolution | Answers in Genesis [Last Updated On: September 2nd, 2016] [Originally Added On: September 2nd, 2016]
- Evolution (2001) - Rotten Tomatoes [Last Updated On: September 18th, 2016] [Originally Added On: September 18th, 2016]
- Human evolution - Wikipedia, the free encyclopedia [Last Updated On: September 22nd, 2016] [Originally Added On: September 22nd, 2016]
- Evolution - Wikipedia [Last Updated On: October 20th, 2016] [Originally Added On: October 20th, 2016]
- MyEvolution // About Evolution [Last Updated On: December 9th, 2016] [Originally Added On: December 9th, 2016]
- Evolution of the Web [Last Updated On: December 10th, 2016] [Originally Added On: December 10th, 2016]
- Evolution | Pokmon Wiki | Fandom powered by Wikia [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Evolution - RationalWiki [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Tracking the Evolution of Student Success - Inside Higher Ed [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Ivanka Trump's Beauty Evolution, From 1998 to Today Watch - Us Weekly [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Lumpy, hairy, toe-like fossil could reveal the evolution of molluscs - The Guardian [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- USM Darwin Day: 'Genesis' a parallel to evolution - The Student Printz [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Cultural evolution and the mutilation of women - The Economist [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- How Evolution Alters Biological Invasions - ScienceBlog.com (blog) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Psychonauts in the Rhombus of Ruin Feels Like an Evolution of Double Fine's Adventure Game Roots - UploadVR [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- The Evolution of Accessible Travel: 5 Podcast Takeaways - Skift [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Convergent Evolution: Why Some Plants Became Carnivorous - Science 2.0 [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- The Queer Evolution of Kristen Stewart - Advocate.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Gold's Gym Regina rebrands to become Evolution Fitness - Regina Leader-Post [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Late-night hosts on the evolution of Trump: 'Dickish to dictatorish' - The Guardian [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Exhibition charts 500 years of evolution of robots - Phys.Org [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Blockchain: Investment (R)Evolution For Developing Markets - Forbes [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- See the Evolution of the Famed Porsche 911 in 7 Photos - WIRED [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How evolution turned ordinary plants into ravenous meat-eaters - Wired.co.uk [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Are Evolution Fresh Drinks 'Poison'? - snopes.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- The Evolution and Maturation of HPC in the Enterprise - CIO [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- From Whoa to 'Wick:' The Evolution of Keanu Reeves - Film School Rejects [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- 'Goldilocks' genes that tell the tale of human evolution hold clues to variety of diseases - Science Daily [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- London exhibition charts 500 years of evolution of robots - Chicago Sun-Times [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Chimpanzee feet allow scientists a new grasp on human foot ... - Science Daily [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- 'Evolution To Revolution' As New York Fashion Week Gets Political - NPR [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Orangutan squeaks reveal language evolution, says study - BBC ... - BBC News [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Deeper origin of gill evolution suggests 'active lifestyle' link in early ... - Science Daily [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Horse evolution bucks evolutionary theory - Science News [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- From Tara Palmer-Tomkinson to Cara Delevingne: the evolution of the It girl - The Guardian [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Evolution gives rhyme its reason - Aurora News Register [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Evolution of in-car audio tech moving at 'speed of sound' - Times of India [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Scientists solve fish evolution mystery - Phys.Org [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- The Difference Between Healthy Love & Unhealthy Love - Collective Evolution [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- This Woman Was Raped & Forgave Him, So They Did A Ted Talk Together - Collective Evolution [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- A primer on Darwin Day: Some religious groups embrace 'Theistic evolution' - LancasterOnline [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Pokmon Go Eevee evolution: How to evolve Eevee into Vaporeon, Jolteon and Flareon with new names - Eurogamer.net [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Evolution of baseball from power to speed has left SBs behind - Chicago Sun-Times [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- More order with less judgment: An optimal theory of the evolution of cooperation - Science Daily [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- How the horse can help us answer one of evolution's biggest questions - Raw Story [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- China Is Now The World's Largest Producer of Solar Power ... - Collective Evolution [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Community Viewpoint: Evolution, like gravity, is much more than theory it is a fact - Kdminer [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- See the Evolution of Movie Magic With Every Oscar Winner for ... - Gizmodo [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- How the horse can help us answer one of evolution's biggest questions - Phys.Org [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- How evolution alters biological invasions - Phys.Org [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- The Evolution of Valentine's Day - Inside Science News Service [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Why evolution may be tech billionaires' biggest enemy - The Week Magazine [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Russell Westbrook is leading an evolution in NBA rebounding - Washington Post [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Eye Evolution: A Closer Look - Discovery Institute [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- How evolution alters biological invasions -- ScienceDaily - Science Daily [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Evolution always wins: University of Idaho video game uses mutating aliens to teach science concepts - The Spokesman-Review [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Geneticists track the evolution of parenting - Phys.Org [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- How this cockeyed squid shines a light on deep sea evolution - Christian Science Monitor [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Cockeyed squid shines light on deep sea evolution - Christian Science Monitor [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]