How Does DevSecOps Integrate Security Globally?

575 views
•
June 22, 2018
by
RSAC Cybersecurity
YouTube video player
How Does DevSecOps Integrate Security Globally?

TL;DR

DevSecOps integrates security throughout development, operations, quality assurance, and application delivery instead of treating it as a separate checkpoint. Organizations should add security controls and quality checks across the delivery pipeline, identify vulnerabilities early, avoid sending known defects into production, and build a shared security mindset among every engineering discipline.

Transcript

Hello, and welcome to this RSA Conference virtual session, DevSecOps is a Global Movement, APJ Included. I am your host, Erika Shubin of RSA Conference. During the session, all participants will be in listen-only mode. At the close of the presentation, we will conduct a question and answer session. Throughout the presentation, if you have a questio... Read More

Key Insights

  • DevSecOps is a natural evolution of DevOps that incorporates security into the existing relationship among development, operations, quality assurance, and application delivery. The disciplines should overlap so thoroughly that security becomes part of normal engineering work rather than a separate organizational concern.
  • Security integration is needed throughout the delivery pipeline, not merely at one shared touchpoint. Controls placed at different pipeline stages can identify vulnerabilities and provide continuous information about the security quality of an application before it reaches consumers or enters production.
  • The guiding principle is to optimize the entire system and never knowingly pass a defect downstream. When teams discover a security vulnerability or another quality problem, they should resolve it before production instead of allowing a known issue to advance through delivery.
  • Application quality includes security as well as the checks traditionally performed by development and quality assurance teams. Blending security findings with their feedback provides a more complete picture of the product and helps teams judge whether it is ready for consumers.
  • A security mindset is expected across engineering roles, including security specialists, developers, operations staff, and quality assurance professionals. The panel argues that organizational culture should make secure behavior part of everyone's work because consumers trust products to perform safely as promised.
  • Consumer trust depends on products functioning as promised without compromising personal information. DevSecOps connects this responsibility directly to the engineering process by embedding security thinking and controls in the activities that create, test, and deliver software.
  • DevSecOps is described as a worldwide phenomenon wherever DevOps and security are present. The discussion specifically identifies activity across the United States, Europe, China, Singapore, the Asia-Pacific region, South America, the Middle East, and Africa.
  • DevSecOps Days is a community-led movement intended to help people bring DevSecOps discussions to their local areas. Its model draws inspiration from DevOps Days unconferences and Security BSides events, while offering resources and information for organizing and attending events.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is the difference between DevOps and DevSecOps?

DevOps connects development and operations around the process of delivering applications, while DevSecOps adds security throughout that same pattern. The panel does not describe the two approaches as competitors. Instead, DevSecOps is the natural evolution of DevOps, with security integrated across development, operations, quality assurance, and application delivery rather than isolated as a separate function.

Q: How should security be integrated into a DevOps pipeline?

Security should be inserted at multiple steps throughout the development and delivery pipeline. Appropriate controls and security quality checks provide information about the application as it progresses. Teams can combine those findings with feedback from development and quality assurance, identify vulnerabilities before release, and prevent known security defects from being passed downstream into production.

Q: Why should organizations avoid treating security as a separate checkpoint?

A separate checkpoint does not reflect the panel's vision of full integration. Security should overlap with development, operations, quality assurance, and delivery so that every activity contributes to a secure product. The panel suggests blurring the boundaries among these disciplines, making security a routine part of engineering decisions rather than a limited touchpoint near the end.

Q: What does it mean to never pass a defect downstream?

Never passing a defect downstream means that a team should not knowingly allow an identified problem to continue through the pipeline or reach production. The principle applies to security vulnerabilities as well as other quality defects. If a problem is known, the team should fix it, while recognizing that different kinds of defects may receive different priorities.

Q: Who is responsible for security in a DevSecOps organization?

Security is a shared responsibility among engineers of every type, including security professionals, developers, operations staff, and quality assurance teams. Each group should develop a security mindset and contribute relevant checks throughout delivery. This shared culture supports products that work as promised and do not compromise the personal information entrusted to them by consumers.

Q: How does DevSecOps improve understanding of application quality?

DevSecOps adds security controls and vulnerability findings to the quality information already produced by developers and quality assurance teams. Combining these perspectives gives the organization a broader view of the complete product. Teams can assess both general application quality and security quality as software moves through the pipeline, rather than evaluating either dimension in isolation.

Q: Why is DevSecOps considered a global movement?

The presenters report seeing DevSecOps take hold wherever DevOps and security are active. They name the United States, Europe, China, Singapore, the wider Asia-Pacific region, South America, the Middle East, and Africa. The movement is therefore framed as an international response to the need for security within modern software development and delivery practices.

Q: What is the purpose of DevSecOps Days?

DevSecOps Days is a community movement designed to encourage local events and worldwide participation around DevSecOps. It is patterned after DevOps Days unconferences and Security BSides conferences. Its website provides information about upcoming gatherings, resources, and guidance for people who want to become involved or bring a DevSecOps event to their own area.

Summary & Key Takeaways

  • DevSecOps is presented as the natural evolution of DevOps, driven by the need for security to match modern application delivery. Rather than placing security beside development and operations, organizations should integrate it throughout the workflow so software quality includes security, functionality, and protection of consumers' personal information.

  • Security controls should operate at multiple points in the development pipeline, producing information about an application's security quality as it progresses. Combining those findings with feedback from developers and quality assurance teams gives the organization a fuller view of the product and helps prevent known defects from reaching production.

  • DevSecOps is described as a global community movement extending across the United States, Europe, China, Singapore, the wider Asia-Pacific region, South America, the Middle East, and Africa. DevSecOps Days encourages local communities to organize events modeled on collaborative movements such as DevOps Days and Security BSides.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚