Unstoppable force meets immovable object
https://en.wikipedia.org/wiki/Nuclear_fusion

Unstoppable force meets immovable object

DevOps is a mindset that has changed the way we view, manage and interact with Information Technology teams and systems. At times it can seem like nothing can stop the progression from traditionally segregated development and operations practices to self-determining expert teams.

In larger organisations however we do see more resistance from well-established operations teams that question the validity of decentralised governance and self-managed production environments. Possibly the most "immovable" concerns come from that of the security teams that are tasked with ensuring protection of organisational and customer data.

Governance has long been a cornerstone of Information Security, with a default assumption that all systems are insecure unless proven otherwise. This burden of proof is often enforced by conforming to a checklist of security requirements that is both lengthy and, in an attempt to address all concerns for all systems, often irrelevant or a waste of time in some aspects. More importantly however, conforming to security requirements is often an afterthought that is addressed only after the system has been designed.

To highlight that security principles need to be considered earlier in the design phase a new term of DevSecOps was coined, which signifies a more pro-active approach to security. It is questionable whether a new term is required at all, as a good DevOps practitioner should always have security in mind, however it does signal that DevOps is not just the "wild wild west" that many security experts might assume it to be.

In fact, when designed for security from the start IT systems will be more secure than any governance processes can dictate, as the security controls will be both relevant and targeted specifically to the design of the system, resulting in less waste and greater efficiency in both design and complexity. Most importantly, designing for security keeps the control in the hands of the expert teams that are most qualified to develop, maintain and support modern IT systems.

Anil Petwal ????

IT strategy & cloud Transformation

5 年

Ben in your view. Cloud agnostic foundation for microservices on IaaS would be good option or PaaS with cloud native foundation with vendor locking ?

回复

要查看或添加评论,请登录

Ben Fortuna的更多文章

  • The AI Doctor will heal your pain

    The AI Doctor will heal your pain

    We have all heard the hype about AI and how it will transform your working life, but how exactly? If you want to…

    1 条评论
  • Building Cloud infrastructure with ChatGPT

    Building Cloud infrastructure with ChatGPT

    With the steady migration towards Cloud infrastructure it is preferable to avoid manual or "Click-ops" infrastructure…

  • The DevOps Rebellion

    The DevOps Rebellion

    If you follow the popular technology news and blogs you would have noticed them to be declaring the death of DevOps in…

    1 条评论
  • What comes first: Skills or Experience?

    What comes first: Skills or Experience?

    It's a prevailing chicken vs egg question: does proven experience trump qualifications, or vice versa? Usually it is a…

  • The Importance of Transferable Skills

    The Importance of Transferable Skills

    Transferable skills are what we consider to be those learnings and abilities we can use in future roles and life in…

  • The importance of soft skills

    The importance of soft skills

    We often overlook the importance of soft skills in IT as we become attuned to the binary nature of the systems we build…

    2 条评论
  • 2021: Return of the monolith

    2021: Return of the monolith

    Recently you may have noticed a growing unease with the trend towards microservices architectures, and a call to return…

    4 条评论
  • A culture of learning with DevOps

    A culture of learning with DevOps

    Contrary to common belief, DevOps is not just about learning more of the operational aspects of IT systems, nor is it a…

  • Defining boundaries

    Defining boundaries

    With the introduction of DevOps over a decade ago the traditional boundaries of responsibility were all but abandoned…

  • Solo: A DevOps Story

    Solo: A DevOps Story

    The challenge of "You build it. You run it!" that is often attached to a DevOps operating model can be daunting to many…

社区洞察