DZone
Thanks for visiting DZone today,
Edit Profile
  • Manage Email Subscriptions
  • How to Post to DZone
  • Article Submission Guidelines
Sign Out View Profile
  • Post an Article
  • Manage My Drafts
Over 2 million developers have joined DZone.
Log In / Join
Refcards Trend Reports Events Over 2 million developers have joined DZone. Join Today! Thanks for visiting DZone today,
Edit Profile Manage Email Subscriptions Moderation Admin Console How to Post to DZone Article Submission Guidelines
View Profile
Sign Out
Refcards
Trend Reports
Events
Zones
Culture and Methodologies Agile Career Development Methodologies Team Management
Data Engineering AI/ML Big Data Data Databases IoT
Software Design and Architecture Cloud Architecture Containers Integration Microservices Performance Security
Coding Frameworks Java JavaScript Languages Tools
Testing, Deployment, and Maintenance Deployment DevOps and CI/CD Maintenance Monitoring and Observability Testing, Tools, and Frameworks
Partner Zones AWS Cloud
by AWS Developer Relations
Culture and Methodologies
Agile Career Development Methodologies Team Management
Data Engineering
AI/ML Big Data Data Databases IoT
Software Design and Architecture
Cloud Architecture Containers Integration Microservices Performance Security
Coding
Frameworks Java JavaScript Languages Tools
Testing, Deployment, and Maintenance
Deployment DevOps and CI/CD Maintenance Monitoring and Observability Testing, Tools, and Frameworks
Partner Zones
AWS Cloud
by AWS Developer Relations
  1. DZone
  2. Software Design and Architecture
  3. Security
  4. DevSecOps Is Suddenly Strategic for Everyone in Software

DevSecOps Is Suddenly Strategic for Everyone in Software

Making DevSecOps a reality for your organization might sound like a daunting task. In reality, however, it's surprisingly easy.

Matt Howard user avatar by
Matt Howard
·
Mar. 09, 17 · Opinion
Like (0)
Save
Tweet
Share
4.45K Views

Join the DZone community and get the full member experience.

Join For Free

Software innovation is the core of every company's digital transformation; the strategic weapon by which modern organizations compete and win on a global playing field. This is why executives and shareholders at every company, in every industry, are placing intense pressure upon IT teams to accelerate innovation.

This insatiable demand for innovation has created a perfect storm which is wreaking havoc on many IT organizations around the world. To counter the effects of this storm, forward-leaning organizations have embraced DevOps as the preferred methodology for manufacturing quality software at scale and continuously delivering innovation.

Organizations everywhere are now transforming their development from waterfall-native to DevOps-native tools and processes. Along the way, they are coming to grips with one simple fact: DevOps is not an excuse to do application security poorly; rather it is an opportunity to do application security better than ever.

This realization is the reason why DevSecOps in suddenly strategic for anyone and everyone in software.

Yesterday's announcement by CA that they are acquiring Veracode for $615 million provides further evidence of this important trend within the software industry. Ayman Sayed from CA stated:

In today’s app economy, companies are aggressively moving to Agile and DevOps practices to speed delivery of new applications. From building and testing to deployment and operations, speed and quality is of the essence. And even more importantly, to effectively secure applications at the speed of DevOps, security needs to be completely integrated into the development process, from start to iteration to general availability and use.

Another reason why DevSecOps is strategic is the fact that 90% of security incidents result from exploits against defects in software. Furthermore, recent research from Gartner predicts that by 2019 more than half of enterprise DevOps initiatives will include automated application security testing; up from 10 percent in 2016.

In traditional Waterfall-native development, implementing software security controls has been cumbersome and difficult to scale. The sad truth is that within most companies, members of the "dev tribe" view members of the "sec tribe" as nothing more than friction and inhibitors to innovation.

Going forward, things must change. Modern teams must learn how to embrace the spirit of DevSecOps and find ways to develop software with one eye on security, one eye on quality, and both eyes on the prize of faster innovation.

Making DevSecOps a reality for your organization might sound like a daunting task. In reality, however, it's surprisingly easy. All you need to do is embrace software supply chain automation tools that infuse lightweight and contextual controls into every phase of your continuous delivery pipeline. You, your CEO, and your shareholders will be amazed at the productivity gains that can happen when your developers view security and governance controls not as inhibitors to innovation — but rather as enablers of innovation.

Software Application security

Published at DZone with permission of Matt Howard, DZone MVB. See the original article here.

Opinions expressed by DZone contributors are their own.

Popular on DZone

  • Top 10 Best Practices for Web Application Testing
  • GitLab vs Jenkins: Which Is the Best CI/CD Tool?
  • What Are the Benefits of Java Module With Example
  • How Chat GPT-3 Changed the Life of Young DevOps Engineers

Comments

Partner Resources

X

ABOUT US

  • About DZone
  • Send feedback
  • Careers
  • Sitemap

ADVERTISE

  • Advertise with DZone

CONTRIBUTE ON DZONE

  • Article Submission Guidelines
  • Become a Contributor
  • Visit the Writers' Zone

LEGAL

  • Terms of Service
  • Privacy Policy

CONTACT US

  • 600 Park Offices Drive
  • Suite 300
  • Durham, NC 27709
  • support@dzone.com
  • +1 (919) 678-0300

Let's be friends: