From Months to Minutes, Deploying with DevOps
Christopher Skinner
Identity and Access Management Analyst | Innovation Office at BlackRock | Infosec & Aladdin Permissions
Less than a year ago, I made the decision to retrain in IT. I was excited but not exactly sure where I would fit into this vast and constantly evolving space. I want to add concrete value to people’s lives, to build secure assets and work in an environment where I can communicate and collaborate with colleagues. I want to continuously learn, improve and look forward.?
Reading industry reports (a more raucous Saturday night) I learned about the differences between elite DevOps practitioners and more traditional approaches. The elite practitioners demonstrated:
These are not typos. I checked. What would traditionally take months, now takes minutes.?
So what is DevOps? What about DevSecOps??
Each model is composed of three teams; developers, operations and security. Each has different roles and priorities.?
In the beginning there was development, operations and security as three separate teams. Developers built, finished their work and sent their software to the operations team. Operations would have to overcome compatibility issues and bugs with them no longer being the developers’ problem. Security would try to ring fence the vulnerabilities at the end. This siloed approach had a number of flaws; distinct, siloed teams with clashing priorities would create buggy apps, typically with no security by design, that take inordinate amounts of time to develop and deploy.
DevOps merges development and operations into one team, enabling collaboration and communication through collective responsibility. Security is embedded at every stage of production. There may be security champions in the DevOps team but there also remains a separate security team with a governance function. DevSecOps integrates all three together.?
[Source Mercari]
The potential upsides are huge; quicker releases, faster bug fixes, more automation and potentially improved security. Potentially. Depending on implementation.?
A less rosy report shared:
and?
领英推荐
A risk of DevSecOps is that security becomes a resource rather than a governance feature with vetoing power, subject to the sway of ever increasing time pressures. This can lead to quicker releases but with more mistakes, and more costly mistakes. Ultimately, whether the journey from DevOps to DevSecOps is right for an organisation depends on its security posture, its risk tolerance and the degree to which it embodies the principles and pillars of secure DevOps and DevSecOps.?
Different Approaches
For the Cloud Security Alliance, a DevSecOps approach rests on 6 pillars of reflexive security. The approach should:
The Department of Defence’s 4 pillars of DevSecOps approach from a different angle addressing people, processes, technology and governance. It includes:
Organisation
Process
Technology?
and?
Governance
As I deep dive into each topic in DevSecOps, developing my knowledge and practice. I’ll be posting my notes. If you’ve made it this far, leave a comment or a question. What made you think? What topics would you like to hear more about? Is there anything I’ve missed or mistaken? Let me know!
Cyber & Information Security Professional - MBA | MSc | Ce-CSP | CCSK | CISMP | CIS IA -ISO 27001:2022 | COMPTIA Sec+ |
2 年Soar Chris, soar! The cyber world awaits your expertise and your gifts. You’ve got this. Can’t wait to see where this beautiful journey takes us all.
CISO @ Owkin (Ex Flo Health and FanDuel)
2 年Would like to see a topic covering culture of security ??
Website builder
2 年Nice overview Chris. Are you planning on looking at specific areas or just let the learning lead you so to speak?